ASEC
Closing the Exposure Window00
News 28.07.2026 4 min read

Three CVEs in a widely deployed ground control station.

DisclosureUAS

Coordinated disclosure complete. Patches available. Details of the chain, now that operators have had time to update.

Three vulnerabilities we reported ninety days ago have been fixed and assigned identifiers. All three are in the same ground control station, and chained they take an attacker on the operator network to arbitrary command execution on the host.

  • An unauthenticated local service used for plugin discovery.
  • A path traversal in mission file import.
  • A privileged helper that accepted commands from any local process.

The vendor responded within four days and shipped a fix in six weeks. That is a good outcome and worth saying out loud — coordinated disclosure works when the vendor engages.

Operators should confirm they are on the current release. If you run this software on a shared laptop in a vehicle, this is the week to check.

Same stack. Different aircraft.

If this reads like something in your programme, it probably is. Send us the architecture and we'll come back with a scope.

Talk to us

News
28.08.2026

DC416 turns ten.

The Toronto DEFCON group our founder started in 2016 is now 2,880 people. Where hackers meet hackers, still, ten years on.

3 minRead →
News
20.08.2026

Two books, both still on the shelf: Black Hat GraphQL and Black Hat Bash.

Our founder co-wrote both for No Starch Press. They exist because the material did not, and clients kept asking where to send their engineers.

3 minRead →
News
12.08.2026

ASEC joins the Canadian drone security working group.

Contributing our engagement data on flight controller, link, and ground station findings to a shared national picture.

2 minRead →