PT-2026-29340 · Unknown · Px4-Autopilot

Dolev Aviv

·

Published

2026-03-31

·

Updated

2026-04-15

·

CVE-2026-1579

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PX4 Autopilot (affected versions not specified)
Description The MAVLink communication protocol, as used by PX4 Autopilot, does not require cryptographic authentication by default. Without MAVLink 2.0 message signing enabled, unauthenticated parties with access to the MAVLink interface can send messages, including the SERIAL CONTROL message which provides interactive shell access. Enabling MAVLink 2.0 message signing in PX4 provides cryptographic authentication and rejects unsigned messages at the protocol level. The SERIAL CONTROL message allows for remote shell access.
Recommendations Enable MAVLink 2.0 message signing to provide cryptographic authentication for all MAVLink communication.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-1579

Affected Products

Px4-Autopilot