ASEC
Closing the Exposure Window00
Research 14.05.2026 8 min read

Debug ports we found on production aircraft.

HardwareUAS

JTAG, UART, and a shell. What OEMs leave enabled when the schedule slips.

Every board has debug access during development. The question is whether the decision to remove it was made by an engineer or by nobody.

14Production boards
09Debug access present
05Dropped to a root shell

What we look for

  • Populated headers and test pads with recognisable pinouts.
  • UART traffic at boot — a console that prints is a console that listens.
  • JTAG/SWD availability and whether read-out protection is set.
  • Bootloader command interfaces reachable over the same pins.

The counter-argument, answered

Manufacturers tell us physical access is out of scope because the aircraft is in the air. Aircraft come down. They come down in places you do not control, and they are recovered by people you did not sell to. Physical access is the baseline assumption for anything that leaves the ground.

Same stack. Different aircraft.

If this reads like something in your programme, it probably is. Send us the architecture and we'll come back with a scope.

Talk to us

Research
08.10.2026

Infected Drones: when the aircraft attacks the ground station.

Six ground-control and middleware projects, fifteen findings, one broken trust boundary. A compromised drone does not have to stay on the vehicle — it can reach up the command chain and own the operator.

9 minRead →
Research
02.09.2026

Damn Vulnerable Drone: a whole aircraft you are allowed to break.

The training range we build and maintain in the open — a simulated airframe, ground station, and radio link, free for anyone learning to attack autonomous systems.

4 minRead →
Research
19.08.2026

MAVLink without a seatbelt.

A field study of telemetry links across eleven commercial aircraft, and what it takes to fly one from the ground.

12 minRead →