Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86714— PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman

Quick assessment

Affected
PX4 PX4-Autopilot
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PX4 Autopilot PX4是PX4 Autopilot组织开源的一款面向无人载具的飞行控制与自主导航软件系统。 PX4 Autopilot PX4 1.17.0及之前版本存在缓冲区错误漏洞,该漏洞源于netman系统命令未验证接口名称长度,导致栈缓冲区越界读取,攻击者可通过-i选项提供74字节或更长的接口名称,造成栈内存泄露至控制台输出或写入持久网络配置文件。

CVSS 5.4 · Medium EPSS 0.33% · P24

Affected Version Matrix 1

VendorProduct Version RangeStatus
PX4 PX4-Autopilot ≤ 1.17.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86714

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman
Source: CVE Program / CVE List V5
Vulnerability Description
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
PX4 Autopilot PX4 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PX4 Autopilot PX4是PX4 Autopilot组织开源的一款面向无人载具的飞行控制与自主导航软件系统。 PX4 Autopilot PX4 1.17.0及之前版本存在缓冲区错误漏洞,该漏洞源于netman系统命令未验证接口名称长度,导致栈缓冲区越界读取,攻击者可通过-i选项提供74字节或更长的接口名称,造成栈内存泄露至控制台输出或写入持久网络配置文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
PX4 PX4-Autopilot 0 ~ 1.17.0 -

II. Public POCs for CVE-2026-86714

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86714

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-86714 (2)

Vendor Advisories for CVE-2026-86714 (1)

Vendor Pages for CVE-2026-86714 (1)

Other References for CVE-2026-86714 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86714

No comments yet


Leave a comment