CVE-2026-86714
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface n
CVSS
5.4
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-125
Sin historial EPSS suficiente todavía.
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
- github.comhttps://github.com/PX4/PX4-Autopilot
- github.comhttps://github.com/PX4/PX4-Autopilot/blob/v1.17.0/src/systemcmds/netman/netman.cpp
- github.comhttps://github.com/PX4/PX4-Autopilot/commit/fec216e9d716d96d93b9d882b0c9cf00db3c6810
- github.comhttps://github.com/PX4/PX4-Autopilot/pull/28483
- www.vulncheck.comhttps://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-buffer-over-read-via-netman
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-858755.5 MED—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.1hCVE-2026-840017.5 ALT—
———Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.1hCVE-2026-839897.5 ALT—
———Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.1hCVE-2026-835015.5 MED—
———Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.1hCVE-2026-819577.8 ALT—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.1hCVE-2026-819567.8 ALT—
———Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.1h