Stack Buffer Over-Read Vulnerability in PX4 Autopilot by PX4
CVE-2026-86714
5.3MEDIUM
What is CVE-2026-86714?
The PX4 Autopilot, up to version 1.17.0, is susceptible to a stack buffer over-read vulnerability within the netman system command. This vulnerability arises due to a failure to adequately validate the length of interface names. Attackers can exploit this flaw by providing interface names that are 74 bytes or longer through the -i option. As a result, sensitive stack memory can be leaked to the console output or inadvertently written into persistent network configuration files, posing significant security risks.
Affected Version(s)
PX4-Autopilot 0 <= 1.17.0
