Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105105— Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

Quick assessment

Affected
NASA-AMMOS AIT-Core
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CWE-306:关键功能缺少身份验证。在 NASA-AMMOS AIT-Core 3.1.1 及之前版本中,ait.core.server 遥测和命令代理(ait-server)存在此漏洞。网络访问 ZeroMQ 消息总线的未经身份验证的远程攻击者可以注入航天器命令数据、窃听命令和遥测流量、注入伪造的遥测数据,或扰乱命令和遥测总线。 默认情况下,ait-server 的 ZeroMQ 代理将 XSUB 和 XPUB 套接字绑定到所有网络接口,且未启用身份验证或传输安全机制。攻击者若能访问 TCP 端口 5559,即

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
NASA-AMMOS AIT-Core ≤ 3.1.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105105

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration
Source: CVE Program / CVE List V5
Vulnerability Description
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
NASA-AMMOS AIT-Core 0 ~ 3.1.1 -

II. Public POCs for CVE-2026-105105

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105105

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105105 (2)

Other References for CVE-2026-105105 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105105

No comments yet


Leave a comment