VendorsDronecodepx4_drone_autopilot1.17.0
Vulnerabilities

Dronecode PX4 Drone Autopilot 1.17.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-32706
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
Published 2026-03-13 · Modified
8.1EPSS 0.003
CVE-2026-32708
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)
Published 2026-03-13 · Modified
8.0EPSS 0.002
CVE-2026-32709
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)
Published 2026-03-13 · Analyzed
6.8EPSS 0.005
CVE-2026-32705
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
Published 2026-03-13 · Modified
6.8EPSS 0.003
CVE-2026-32713
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors
Published 2026-03-13 · Analyzed
6.5EPSS 0.004
CVE-2026-32743
PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
Published 2026-03-18 · Analyzed
6.5EPSS 0.004
CVE-2026-32707
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
Published 2026-03-13 · Modified
6.1EPSS 0.003
CVE-2026-32724
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition
Published 2026-03-13 · Analyzed
5.3EPSS 0.003