CPATH-2026-0028 · Robotics / humanoid

Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsPerception-to-action + Device-control safety + Device availability and recovery

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Perception · Co-dominant path

Perception-to-action

The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.

CRITICAL
  1. accessModel inference

    Proximity or local access

    Network intermediary control position on the control path.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  2. boundaryModel inference

    Reusable multi-stage bridge

    The attack crosses from the control network into robot motion and then into the physical surgical environment.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception-to-action

    The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Operators can abort and re-establish the control link, but restoring trustworthy operation also requires protecting the command channel from repeated interception.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Network intermediary control position on the control path.

Model inference
Execution complexityEC 2
Specialist multi-step technique

The attacker must first intercept the teleoperation link; once on path, command or feedback injection is straightforward and repeatable.

Model inference
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Manipulated command or feedback state directly drives a patient-manipulating robot, so false control state can create a severe procedural hazard.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.

Model inference
AuthorityAT 3
Administrative or command authority

The injected packet reaches command authority over robot motion, but not operating-system root or the firmware signing boundary.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

The attack crosses from the control network into robot motion and then into the physical surgical environment.

Model inference
Reuse scaleSR 3
Portable product-class technique

The protocol weakness can recur wherever the same unauthenticated control channel is deployed, but it does not expose a shared key.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each attack remains tied to one reachable control link and deployment; there is no fleet mechanism.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Operators can abort and re-establish the control link, but restoring trustworthy operation also requires protecting the command channel from repeated interception.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Model inference
LivenessLS Historical
Historical condition

The condition is retained as a historical case rather than a claim of current field exposure.

Operational assumption

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:4/DP:4/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →

Safety · Co-dominant path

Device-control safety

Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.

CRITICAL
  1. accessModel inference

    Proximity or local access

    Network intermediary control position.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  2. boundaryModel inference

    Reusable multi-stage bridge

    The attack crosses from an intercepted network control channel into robot motion at the patient boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Operators must restore the trusted control link, verify robot state, and determine whether the interrupted procedure can safely continue.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Network intermediary control position.

Model inference
Execution complexityEC 2
Specialist multi-step technique

Reproducible intermediary control, simple injection once positioned.

Model inference
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The intercepted channel carries the live command and control state used to move the surgical robot.

Model inference
AuthorityAT 3
Administrative or command authority

The injected packet reaches command authority over robot motion, but not operating-system root or the firmware signing boundary.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

The attack crosses from an intercepted network control channel into robot motion at the patient boundary.

Model inference
Reuse scaleSR 3
Portable product-class technique

The injection method can be reused wherever the same unprotected teleoperation protocol is deployed.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each attack remains tied to one reachable robot-control session and does not provide a fleet execution mechanism.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Operators must restore the trusted control link, verify robot state, and determine whether the interrupted procedure can safely continue.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Model inference
LivenessLS Historical
Historical condition

The condition is retained as a historical case rather than a claim of current field exposure.

Operational assumption

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →

Recovery · Co-dominant path

Device availability and recovery

Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.

CRITICAL
  1. accessModel inference

    Proximity or local access

    The attacker needs an on-path position on the robot’s control network to inject or suppress session traffic.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  2. boundaryModel inference

    One cross-boundary bridge

    The packet crosses from the control network into the robot’s safety state, but it does not create a broader reusable authority chain.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Credible safety consequence

    Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Operators must restore the trusted control link, verify robot state, and decide whether the interrupted procedure can safely resume.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker needs an on-path position on the robot’s control network to inject or suppress session traffic.

Model inference
Execution complexityEC 3
Reproducible exploit workflow

Standard once positioned but notably efficient (single packet).

Model inference
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.

Model inference
Data / perceptionDP 1
Low-sensitivity state

This path interrupts the control session and does not depend on reading or changing patient data.

Model inference
AuthorityAT 2
Bounded function authority

Triggering the emergency stop reaches one bounded safety function but does not grant general command, administrator, or firmware authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The packet crosses from the control network into the robot’s safety state, but it does not create a broader reusable authority chain.

Model inference
Reuse scaleSR 3
Portable product-class technique

The denial method is reusable across deployments that use the same unprotected teleoperation protocol.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each interruption requires an on-path position against one active teleoperation link.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Operators must restore the trusted control link, verify robot state, and decide whether the interrupted procedure can safely resume.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Model inference
LivenessLS Historical
Historical condition

The condition is retained as a historical case rather than a claim of current field exposure.

Operational assumption

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:3/EX:2/PH:3/DP:1/AT:2/CH:2/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →

Triage implication

Verify the perception transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

At least one citation still lacks a public URL; that gap keeps this record provisional.

  • other
    source citation pending public URL

    source citation pending public URL · public URL pending

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipNo comparable score
Baseline confidencelow
Scored2026-06-03

No public baseline score is available for this case.

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse at CRITICAL — the worst of 3 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.

Vulnerability

Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse. Reported attack vector: Network (man-in-the-middle on teleoperation link).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:4/DP:4/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL → assessed CRITICAL.

  • Intention-modification: MITM on the unauthenticated/unencrypted teleoperation link lets the attacker read and alter the command/feedback stream so the corrupted perception loop between surgeon and robot drives unintended actuation.
  • RE2 — (network MITM position on the control path; demonstrated on public/shared networks, not internet-default and not victim physical).
  • EC2 — advanced-but-reproducible MITM, but trivial once positioned.
  • AT3 — control-channel/command authority over robot, not OS root or signing root.
  • PH4 — and DP4 because the manipulated feedback/command state is safety-relevant world/control state on a patient-manipulating robot;
  • perception_feeds_action — true.
  • CH3 — crosses console/network/device/physical/safety boundaries.
  • SR3 — protocol-level weakness reuses across deployments using the same unprotected protocol but is not a shared key/artifact.
  • SX2 — per-link/per-deployment proximity, no fleet mechanism.
  • EV3 — reproduced (DSN 2015).

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL → assessed CRITICAL.

  • Full hijacking: attacker gains effective control authority over robot motion without credentials, overriding/ignoring operator inputs to drive dangerous actuation against a patient.
  • RE2 — network MITM position.
  • EC2 — reproducible MITM, simple injection once positioned.
  • AT3 — control/command authority (no root-of-trust or signing key compromised).
  • PH4 — credible patient injury from unintended/maliciously commanded motion;
  • perception_feeds_action — true since the hijacked command stream directly causes safety-relevant physical action.
  • DP3 — control/command state.
  • CH3 — and boundary_crossing across network/device/physical/safety.
  • SR3 — protocol-class reuse.
  • SX2 — per-link, no demonstrated fleet execution.
  • OR2 — recovery is operational (regain link, abort).
  • EV3 — reproduced.

DEVICE_AVAILABILITYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:3/EX:2/PH:4/DP:1/AT:2/CH:2/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL

Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=ELEVATED · AT=ELEVATED → base CRITICAL → assessed CRITICAL.

  • E-stop abuse: a single unauthenticated packet triggers the robot’s own emergency-stop to deny operation mid-procedure.
  • RE2 — network MITM/on-path position.
  • EC3 — standard once positioned but notably efficient (single packet); not EC4 because it still needs an on-path/injection position.
  • AT2 — abuse of a bounded safety/availability control rather than full command authority.
  • PH3 — safety-margin reduction: aborting/halting mid-procedure is disruptive and can reduce safety margin but is the platform’s fail-safe rather than dangerous actuation, so not PH4.
  • DP1 — negligible data impact.
  • CH2 — crosses network/device/safety boundary, limited chainability.
  • SR3 — protocol-class reuse.
  • SX2 — per-link.
  • OR2 — operational recovery (regain link, abort/restart).
  • EV3 — reproduced.

Published baseline

No public baseline score has been published for this finding. It belongs to a perception/control harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.

Sources

  • source citation pending public URL

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0028 (“Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse”), paths.cfse.ai/CPATH-2026-0028 (published 2026-06-03).