Dronecode
Dronecode PX4 Drone Autopilot: vulnerabilidades y CVE
Dronecode PX4 Drone Autopilot tiene 23 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses11
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-32743 | Media (6.5) | 0.33% | — | 19 mar 2026 | PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the MavlinkLogHandler, and are triggered via MAVLink log… |
| CVE-2026-32724 | Media (5.3) | 0.23% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink… |
| CVE-2026-32713 | Media (6.5) | 0.29% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and… |
| CVE-2026-32709 | Media (6.8) | 0.32% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVLink FTP implementation allows any MAVLink peer to read, write, create,… |
| CVE-2026-32708 | Alta (8) | 0.26% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an… |
| CVE-2026-32707 | Media (6.1) | 0.27% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN frames are processed.… |
| CVE-2026-32706 | Alta (8.1) | 0.31% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer without a bounds check.… |
| CVE-2026-32705 | Media (6.8) | 0.28% | — | 16 mar 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provided length without bounds. A malicious BST device can report an… |
| CVE-2026-26742 | Alta (8.1) | 0.29% | — | 10 mar 2026 | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot… |
| CVE-2026-26741 | Alta (8.1) | 0.29% | — | 10 mar 2026 | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the… |
| CVE-2025-15150 | Media (4.8) | 0.25% | — | 28 dic 2025 | A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file… |
| CVE-2024-40427 | Alta (7.9) | 0.35% | — | 7 ene 2025 | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute |
| CVE-2024-38952 | Alta (7.5) | 0.70% | — | 25 jun 2024 | PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp. |
| CVE-2024-38951 | Media (6.5) | 0.53% | — | 25 jun 2024 | A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message. |
| CVE-2024-30800 | Media (5.6) | 0.21% | — | 23 abr 2024 | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function. |
| CVE-2024-30799 | Media (4.4) | 0.26% | — | 22 abr 2024 | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function. |
| CVE-2024-29460 | Media (6.6) | 0.24% | — | 10 abr 2024 | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component. |
| CVE-2024-24255 | Media (4.2) | 0.34% | — | 6 feb 2024 | A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions. |
| CVE-2024-24254 | Media (4.2) | 0.36% | — | 6 feb 2024 | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the… |
| CVE-2023-47625 | Media (4.3) | 0.52% | — | 13 nov 2023 | PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due… |
| CVE-2023-46256 | Crítica (9.8) | 0.63% | — | 31 oct 2023 | PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index`… |
| CVE-2021-46896 | Alta (7.5) | 0.81% | — | 6 jul 2023 | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332. |
| CVE-2021-34125 | Alta (7.5) | 0.96% | — | 9 mar 2023 | An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands. |