ASEC
Closing the Exposure Window00
Research 22.07.2026 14 min read

Signed, but not verified.

FirmwareHardwareUAS

Four vendors shipped secure boot with signature checks that never ran. We show the extraction, the patch, and the fix.

Secure boot is a chain. Every link has to hold, and every link has to actually be executed. In four of the six flight controllers we examined, the verification code was present, correct, and unreachable.

06Controllers examined
04Verification never executed
01Fully chained boot

How verification goes missing

The pattern is the same each time. The primary boot path verifies. A secondary path — recovery, DFU, factory reset, or a vendor update mode — does not, because it was written first, or written by a different team, or written under a deadline.

if (boot_mode == BOOT_NORMAL) {
    if (!verify_signature(image)) fail();
}
jump_to(image);   /* every other boot_mode lands here */

That is a paraphrase, not a quote, but it is the shape of all four findings.

Extraction

  • Locate the debug interface. On three of six it was populated on the production board.
  • Dump flash. Two devices had read-out protection set; one of those could be reset by glitching the supply during boot.
  • Identify the bootloader and the branch that reaches the image without verification.
  • Sign nothing. Flash a modified image through the unverified path.

Why this matters for a manufacturer

Third-party assessment against defence supply-chain standards examines software integrity and secure boot specifically. A verification routine that exists but never runs will not survive that examination — and it will not survive an adversary with physical access to a downed aircraft.

The fix

  • Verify in one place, before the jump, unconditionally. Not per boot mode.
  • Enable read-out protection and test that it is actually set on production units.
  • Treat recovery and DFU as the primary attack path, because they are.
  • Add a boot-path test to CI that asserts an unsigned image is rejected in every mode.

Same stack. Different aircraft.

If this reads like something in your programme, it probably is. Send us the architecture and we'll come back with a scope.

Talk to us

Research
08.10.2026

Infected Drones: when the aircraft attacks the ground station.

Six ground-control and middleware projects, fifteen findings, one broken trust boundary. A compromised drone does not have to stay on the vehicle — it can reach up the command chain and own the operator.

9 minRead →
Research
02.09.2026

Damn Vulnerable Drone: a whole aircraft you are allowed to break.

The training range we build and maintain in the open — a simulated airframe, ground station, and radio link, free for anyone learning to attack autonomous systems.

4 minRead →
Research
19.08.2026

MAVLink without a seatbelt.

A field study of telemetry links across eleven commercial aircraft, and what it takes to fly one from the ground.

12 minRead →