CVE-2026-71641
ZJU-FAST-Lab · EGO-Planner-v2
A denial of service vulnerability in ZJU-FAST-Lab EGO-Planner-v2 exists due to flawed emergency recovery logic in the interaction between system components.
Executive summary
The ZJU-FAST-Lab EGO-Planner-v2 software is susceptible to a denial of service attack that can be triggered by unauthenticated remote actors, potentially halting critical autonomous navigation functions.
Vulnerability
The vulnerability stems from improper handling of emergency recovery logic within the EGOReplanFSM component, triggered by interactions between the traj_server and poscmd_2_odom modules. This allows an unauthenticated attacker to remotely induce a system crash or freeze.
Business impact
Successful exploitation results in a denial of service, which poses a significant risk to systems relying on EGO-Planner-v2 for navigation or robotics control. Given the CVSS score of 7.5, this high severity flaw could lead to operational downtime or the loss of control over autonomous hardware, necessitating immediate attention to maintain system availability and safety.
Remediation
Immediate Action: Currently, no official patch is available: users should monitor the ZJU-FAST-Lab GitHub repository for updates or commit fixes.
Proactive Monitoring: Monitor system logs for unexpected crashes of the traj_server or EGOReplanFSM modules, especially during periods of high network activity.
Compensating Controls: Restrict network access to the affected planning modules using firewall rules to ensure only authorized traffic can interact with the navigation services.
Exploitation status
Public Exploit Available: No (exploit_available: unknown).
Analyst recommendation
Given the high severity of this vulnerability and the potential for remote exploitation, administrators must prioritize the security of the host environment. Until a formal patch is released by the vendor, implement strict network segmentation to isolate the affected components and prevent unauthorized external interactions that could trigger the denial of service condition.
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written