ASEC
Closing the Exposure Window00
Research 19.08.2026 12 min read

MAVLink without a seatbelt.

UASRFProtocol

A field study of telemetry links across eleven commercial aircraft, and what it takes to fly one from the ground.

MAVLink is the lingua franca of small unmanned aircraft. It is also, in its default configuration, a protocol with no authentication, no encryption, and no replay protection. Message signing exists. Almost nobody turns it on.

11Aircraft tested
09Accepted injected commands
02Had signing enabled

Method

We acquired eleven commercially available aircraft across four price tiers, captured the telemetry link on the bench with a software-defined radio, and attempted three escalating actions: read telemetry, inject a benign parameter change, and inject a mode change.

  • Capture: passive receive at the advertised link frequency, no association required on nine of eleven.
  • Inject: craft a valid MAVLink frame with the observed system and component ID.
  • Escalate: mode change to RTL, then to LOITER, then a waypoint upload.

Results

Nine of eleven aircraft accepted an injected mode change from an unassociated transmitter. Two rejected it — both had MAVLink 2 message signing enabled by default, and both were the two most expensive units in the study.

The failure is not in MAVLink. Signing has been in the specification since 2017. The failure is that it ships off, and the integration guides that OEMs follow do not turn it on.

What OEMs should do

  • Enable MAVLink 2 message signing by default and fail closed when the peer does not sign.
  • Provision the link key per aircraft at manufacture. Never derive it from a serial number.
  • Rate-limit and log mode changes at the flight controller, not only at the ground station.
  • Treat the telemetry radio as an untrusted network interface, because that is what it is.

Disclosure

All eleven vendors were contacted. Seven responded. Four have shipped firmware that enables signing by default. The aircraft are not named individually — this is a pattern in the ecosystem, not a story about one vendor.

Same stack. Different aircraft.

If this reads like something in your programme, it probably is. Send us the architecture and we'll come back with a scope.

Talk to us

Research
08.10.2026

Infected Drones: when the aircraft attacks the ground station.

Six ground-control and middleware projects, fifteen findings, one broken trust boundary. A compromised drone does not have to stay on the vehicle — it can reach up the command chain and own the operator.

9 minRead →
Research
02.09.2026

Damn Vulnerable Drone: a whole aircraft you are allowed to break.

The training range we build and maintain in the open — a simulated airframe, ground station, and radio link, free for anyone learning to attack autonomous systems.

4 minRead →
Research
22.07.2026

Signed, but not verified.

Four vendors shipped secure boot with signature checks that never ran. We show the extraction, the patch, and the fix.

14 minRead →