
A collection of vulnerabilities & exploits against modern GCS
Drone-to-Ground Control Station attack vectors, vulnerabilities & exploits
Drone fleets today are one operator flying dozens or hundreds of drones from a single ground station. This makes the ground control station a valuable target for adversaries. It is where the pilot is usually located, it often stores mission data, and it is a prime vector for lateral movement across UxS networks and other drones in a fleet.
Most drone security research has focused on targeting the drone. The Infected Drone research takes an alternative approach and highlights how a single compromised drone can attack ground stations that connect to it. Because most ground control software trusts whatever the drone sends it, there is a lack of authentication, validation, and sanitization, allowing data from a compromised drone to lead to file CRUD, code execution, or a crash on the operator's machine.
This repository documents vulnerabilities in ground control station software and ships working proof-of-concept code for them. It is published for educational purposes only and for operators to understand their exposure and so maintainers can reproduce and fix these issues.
Run the PoCs only against systems you own or have written permission to test. Every one of them is written for a bench: the payloads are benign markers, and nothing here is packaged for use against someone else's aircraft or ground station. Using this material against systems you do not control is likely illegal wherever you are.
Each finding's Reproduction section states what it needs and what it does. Read it before running anything.
Legend:
Delivery class is what the attacker has to do on the link, and it decides which vectors work. Push findings need only a frame arriving at the GCS, so any injection-capable vector is enough. Handshake and request/response findings need the attacker to be, or fully control, the conversational peer, which favours an on-bus peripheral, a compromised companion, the supply chain, or a full MITM.
The Fix column links the upstream pull request where one has been submitted. Ten of the fifteen findings ship with a patch filed against the vendor's own repository.