CVE-2026-86714
Awaiting Analysis Awaiting Analysis - Queue

Stack Buffer Over-Read in PX4 Autopilot

Vulnerability report for CVE-2026-86714, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
px4 autopilot 1.17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PX4 Autopilot through version 1.17.0 has a stack buffer over-read issue in the netman system command. It fails to check the length of interface names provided via the -i option. Attackers can input interface names of 74 bytes or longer, causing the system to read beyond the allocated buffer. This can leak stack memory to the console or write it into network configuration files.

Detection Guidance

To detect this vulnerability, monitor for interface names exceeding 74 bytes in the netman system command output or logs. Check for stack memory leaks in console output when running netman with long interface names. Inspect network configuration files for unexpected data writes.

Impact Analysis

This vulnerability could allow attackers to access sensitive stack memory, potentially exposing confidential data or system details. If exploited, it might also corrupt network configurations by writing invalid data to persistent files. The impact depends on the system's exposure and the attacker's goals.

Mitigation Strategies

Update PX4 Autopilot to version 1.17.0 or later. Restrict access to the netman command to trusted users only. Implement input validation for interface names to ensure they do not exceed 74 bytes. Monitor network configuration files for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86714. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart