top of page
perceptive_background_267k.jpg

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it i…

Published:

15 March 2026 at 23:00:00

Alert date:

16 March 2026 at 16:21:26

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

CVE-2026-32706 affects PX4 autopilot flight control software for drones prior to version 1.17.0-rc2. The vulnerability exists in the crsf_rc parser which accepts oversized variable-length packets and copies them into a fixed 64-byte buffer without bounds checking. An adjacent or raw-serial attacker can exploit this to trigger memory corruption and crash the PX4 system. The issue occurs when crsf_rc is enabled on a CRSF serial port. This represents a significant security risk for drone operations as it can cause flight control system crashes. The vulnerability has been patched in version 1.17.0-rc2.

Technical details

Mitigation steps:

Affected products:

PX4 Autopilot

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page