Bench to full compromise in four days.
A defence UAS prime handed us a production flight controller and asked how far we could get. Far enough that the fix shipped before the next flight test.
The client builds a medium-class aircraft for government customers. Before submitting for third-party assessment they wanted an adversary to reach the autopilot the way a real one would — from the outside, with no source code and no documentation.
The scope
One production aircraft, one ground control station, and the fleet portal that ties them together. No source, no schematics, no vendor contacts. Everything we used is available to anyone who buys the aircraft.
What we found
- A debug UART left populated on the production board, unauthenticated, dropping to a root shell.
- Firmware signature verification implemented but never called on the recovery path.
- Telemetry commands accepted without authentication once the link key was recovered from flash.
- A fleet-portal API token scoped to the whole tenant rather than the single aircraft that held it.
What changed
The recovery-path bug was a two-line fix that nobody would have found by reading the code, because the code looked correct. The UART was a manufacturing decision, not an engineering one. Both are now caught by a pre-release checklist we wrote with their team.
The fleet-portal token scoping took longer — it was an architectural assumption, not a bug. We reviewed the redesign and re-tested it eight weeks later.
ASEC