Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-60113— AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes

Quick assessment

Affected
NASA-AMMOS AIT-DSN
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NASA AIT-DSN是美国NASA政府部门开源的一款深空网络接口工具包,提供基于CCSDS SLE协议的API用于航天器通信设施的连接。 NASA AIT-DSN 2.2.2之前版本存在授权问题漏洞,该漏洞源于Space Link Extension (SLE) interface manager缺少身份验证,导致未经身份验证的网络攻击者可通过发送直接HTTP请求访问未受保护的API路由,从而启动或停止深空网络通信会话、检索遥测帧数据以及向活跃航天器链路注入任意帧。

CVSS 9.8 · Critical EPSS 0.53% · P43

Affected Version Matrix 1

VendorProduct Version RangeStatus
NASA-AMMOS AIT-DSN < 2.2.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-60113

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
Source: CVE Program / CVE List V5
Vulnerability Description
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
NASA AIT-DSN 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NASA AIT-DSN是美国NASA政府部门开源的一款深空网络接口工具包,提供基于CCSDS SLE协议的API用于航天器通信设施的连接。 NASA AIT-DSN 2.2.2之前版本存在授权问题漏洞,该漏洞源于Space Link Extension (SLE) interface manager缺少身份验证,导致未经身份验证的网络攻击者可通过发送直接HTTP请求访问未受保护的API路由,从而启动或停止深空网络通信会话、检索遥测帧数据以及向活跃航天器链路注入任意帧。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
NASA-AMMOS AIT-DSN 0 ~ 2.2.2 -

II. Public POCs for CVE-2026-60113

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10183 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-60113

登录查看更多情报信息。

Patches & Fixes for CVE-2026-60113 (2)

Vendor Advisories for CVE-2026-60113 (2)

Other References for CVE-2026-60113 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-60113

No comments yet


Leave a comment