CVE-2026-75371
SpaceDot · AcubeSAT OBC software
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software allows physically-proximate attackers to trigger a Denial of Service via crafted UART input.
Executive summary
A critical integer handling vulnerability in SpaceDot AcubeSAT OBC software could allow unauthenticated, physically-proximate attackers to cause a system Denial of Service.
Vulnerability
The vulnerability exists within the cobs_decode function, where an integer handling error can be triggered by providing malicious input via a UART interface. This flaw requires physical proximity and access to the UART port, but does not require any prior authentication from the attacker.
Business impact
The exploitation of this flaw results in a Denial of Service, which effectively halts the operation of the On-Board Computer (OBC). Given the critical role of the OBC in satellite operations, this could lead to total loss of mission control or system unavailability. While the CVSS score of 7.5 reflects the high impact on availability, the specialized nature of the hardware necessitates immediate attention to prevent operational disruption.
Remediation
Immediate Action: Contact the vendor, SpaceDot, to obtain the necessary firmware or software patch for the affected commit eaf90ec.
Proactive Monitoring: Monitor UART interface activity and system logs for unexpected reboots or service interruptions that may indicate an attempt to trigger the flaw.
Compensating Controls: Restrict physical access to hardware interfaces and UART ports to authorized personnel only to prevent unauthorized input injection.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability poses a significant risk to mission-critical satellite hardware due to the potential for total Denial of Service. Security teams must prioritize identifying systems running the vulnerable commit and implement physical access controls immediately. Coordinate with SpaceDot to verify the availability of a patched version and apply it as soon as it is released to ensure system resilience.