VendorsDronecodepx4_drone_autopilotany version
Vulnerabilities

Dronecode PX4 Drone Autopilot any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2023-46256
PX4-Autopilot Heap Buffer Overflow Bug
Published 2023-10-31 · Modified
9.8EPSS 0.006
CVE-2026-32706
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
Published 2026-03-13 · Modified
8.1EPSS 0.003
CVE-2026-26742
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.
Published 2026-03-10 · Analyzed
8.1EPSS 0.003
CVE-2026-26741
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the system lacks a throttle threshold safety check for the physical throttle stick. This flaw can directly cause the drone to lose control, experience rapid uncontrolled ascent (flyaway), and result in property damage
Published 2026-03-10 · Analyzed
8.1EPSS 0.003
CVE-2026-32708
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)
Published 2026-03-13 · Modified
8.0EPSS 0.002
CVE-2024-40427
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute
Published 2025-01-07 · Analyzed
7.9EPSS 0.003
CVE-2025-15150
PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow
Published 2025-12-28 · Analyzed
7.8EPSS 0.002
CVE-2021-34125
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
Published 2023-03-09 · Modified
7.5EPSS 0.010
CVE-2021-46896
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
Published 2023-07-06 · Modified
7.5EPSS 0.008
CVE-2026-32709
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)
Published 2026-03-13 · Analyzed
6.8EPSS 0.005
CVE-2026-32705
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
Published 2026-03-13 · Modified
6.8EPSS 0.003
CVE-2026-32713
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors
Published 2026-03-13 · Analyzed
6.5EPSS 0.004
CVE-2026-32743
PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
Published 2026-03-18 · Analyzed
6.5EPSS 0.004
CVE-2026-32707
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
Published 2026-03-13 · Modified
6.1EPSS 0.003
CVE-2026-32724
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition
Published 2026-03-13 · Analyzed
5.3EPSS 0.003
CVE-2024-30799
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.
Published 2024-04-22 · Analyzed
4.4EPSS 0.003
CVE-2024-24254
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes.
Published 2024-02-06 · Modified
4.2EPSS 0.004
CVE-2024-24255
A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.
Published 2024-02-06 · Modified
4.2EPSS 0.003