Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Dominant path
Device-control safety
Attacker can disarm, alter mission, command flight, or crash the vehicle.
Network-reachable without prior access
Any attacker who can reach the MAVLink network or radio interface can target vehicles where message signing remains disabled.
EvidenceNVD
Cross-domain authority chain
The path crosses from network or radio traffic into the flight-controller shell and then into physical vehicle actuation.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Attacker can disarm, alter mission, command flight, or crash the vehicle.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Attacker can disarm, alter mission, command flight, or crash the vehicle.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires enabling MAVLink signing and segmenting control traffic across affected vehicles.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Any attacker who can reach the MAVLink network or radio interface can target vehicles where message signing remains disabled.
- Execution complexity
EC 4 - Straightforward operation
Single crafted SERIAL_CONTROL message, no memory-corruption primitive.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Attacker can disarm, alter mission, command flight, or crash the vehicle.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Shell can read and inject into perception and control loops (navigation, sensor state) that drive flight.
- Authority
AT 4 - Firmware or trust-root authority
The interactive shell reaches the flight controller’s highest operating authority and can change mission or actuation state.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The path crosses from network or radio traffic into the flight-controller shell and then into physical vehicle actuation.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Missing-auth design default in widely deployed open-source firmware, single reused technique, no per-target artifact.
- Execution scale
SX 4 - Remote fleet-scale execution
The same MAVLink command can be repeated against network-reachable PX4 vehicles that have signing disabled, without visiting each airframe.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires enabling MAVLink signing and segmenting control traffic across affected vehicles.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Attacker can disarm, alter mission, command flight, or crash the vehicle.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:4/AT:4/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →Privacy · Supporting path
Data privacy
Remote shell access can expose telemetry, mission plans, and onboard storage containing sensitive operational and proprietary data.
Network-reachable without prior access
The data path uses the same unauthenticated MAVLink shell entry as the safety path, requiring only network or radio reachability.
EvidenceNVD
Reusable multi-stage bridge
The path crosses from the network into the flight controller and then into stored mission and telemetry data, making the shell a reusable extraction bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
Remote shell access can expose telemetry, mission plans, and onboard storage containing sensitive operational and proprietary data.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
Remote shell access can expose telemetry, mission plans, and onboard storage containing sensitive operational and proprietary data.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires enabling MAVLink signing and segmenting control traffic across affected vehicles.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The data path uses the same unauthenticated MAVLink shell entry as the safety path, requiring only network or radio reachability.
- Execution complexity
EC 4 - Straightforward operation
The same single unauthenticated MAVLink message opens the shell; reading telemetry, mission files, or onboard storage requires no second exploit chain.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 0 - No direct physical effect
This path exfiltrates data without directly changing physical behavior or a safety decision.
- Data / perception
DP 3 - Sensitive device or personal data
Remote shell access can expose telemetry, mission plans, and onboard storage containing sensitive operational and proprietary data.
- Authority
AT 4 - Firmware or trust-root authority
The shell grants the flight controller’s highest operating authority, although this path uses it to read mission and telemetry data.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
The path crosses from the network into the flight controller and then into stored mission and telemetry data, making the shell a reusable extraction bridge.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The missing-authentication design is shared across affected PX4 deployments, so the shell technique is portable across vehicles.
- Execution scale
SX 4 - Remote fleet-scale execution
The shell operation can be repeated against any network-reachable PX4 vehicle with signing disabled, without physical access to each one.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires enabling MAVLink signing and segmenting control traffic across affected vehicles.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- Evidence-gated cap
The EMERGENCY base consequence is capped at CRITICAL because this path exposes sensitive mission and telemetry data but does not independently reach a safety-driving perception or physical-control consequence.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:0/DP:3/AT:4/CH:3/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2026-1579
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses PX4 Autopilot MAVLink Unauthenticated Remote Shell (CVE-2026-1579) at EMERGENCY — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
PX4 Autopilot MAVLink Unauthenticated Remote Shell (CVE-2026-1579). Reported attack vector: Network (MAVLink interface, typically UDP/serial/radio link to ground control station).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:4/AT:4/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=EMERGENCY · AT=EMERGENCY → base EMERGENCY · uplift fleet-reachable authority → assessed EMERGENCY.
- RE4 — reachable by anyone with network/radio access to MAVLink, frequently open UDP/unauthenticated radio, default signing disabled.
- EC4 — single crafted SERIAL_CONTROL message, no memory-corruption primitive, AC:L.
- AT4 — interactive shell = total control of the autopilot, the highest-authority component on the vehicle, equivalent to control-plane/firmware-level authority over the flight computer.
- PH4 — attacker can disarm, alter mission, command flight, or crash the vehicle; CISA notes catastrophic physical damage.
- DP4 — shell can read and inject into perception/control loops (nav, sensor state) that drive flight;
- perception_feeds_action — true.
- CH4 — cross-domain bridge from network/radio into device shell and physical actuation, reusable across the fleet;
- boundary_crossing — across link/device/physical/safety.
- SR4 — missing-auth design default in widely deployed open-source firmware, single reused technique, no per-target artifact.
- SX4 — fleet-scale remote, trivially repeatable against any PX4 vehicle with signing disabled, no per-device access needed.
- OR3 — recovery is a configuration/hardening change (enable MAVLink 2.0 signing + network segmentation) across affected vehicles, not a per-device recall or signing-root rotation.
- EV2 — report-backed (CVE/ICSA advisory), not reproduced here.
DATA_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:4/CH:3/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=EMERGENCY → base EMERGENCY · uplift fleet-reachable authority · caps privacy-only cap → assessed CRITICAL.
- Same position (RE4) and execution (EC4) as the control path: unauthenticated MAVLink reachability + single SERIAL_CONTROL message yielding a shell.
- AT4 — full shell authority over the flight controller.
- PH0 — pure data exfiltration path, no direct physical/safety effect.
- DP3 — exfiltration of telemetry, mission data, and onboard storage (operational/proprietary/sensitive-op-state); this read-out does not by itself drive physical action so perception_feeds_action=false.
- CH3 — /boundary_crossing: crosses network/device boundary to extract device-held data, reusable.
- SR4 — same shared missing-auth design default, portable technique.
- SX4 — fleet-scale remote exfiltration without per-device access.
- OR3 — same config/hardening remediation.
- EV2 — report-backed.
Published baseline
- v4.0 9.3 CRITICAL —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— CISA/ICS-CERT via NVD - v3.1 9.8 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— CISA/ICS-CERT via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0017 (“PX4 Autopilot MAVLink Unauthenticated Remote Shell (CVE-2026-1579)”), paths.cfse.ai/CPATH-2026-0017 (published 2026-06-03).