CVE-2026-32743 is a stack-based buffer overflow vulnerability affecting PX4 Autopilot versions 1.17.0-rc2 and below, specifically within the MavlinkLogHandler. An attacker with MAVLink link access can trigger this by creating deeply nested directories via MAVLink FTP and then requesting the log list, exploiting a lack of width specification in the sscanf function. This leads to a Denial of Service (DoS) as the flight controller's MAVLink task crashes, resulting in a loss of telemetry and command capabilities, rated with a CVSS score of 6.5 (Medium). There is currently no evidence of active exploitation, nor are public exploit codes available, and community discussion or media coverage regarding this vulnerability is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:alpha1:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:beta1:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:rc1:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:dronecode:px4_drone_autopilot:1.17.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.