VYPR

essential-moos

by Themoos

CVEs (5)

  • CVE-2026-85433CriSep 3, 2026
    risk 0.57cvss 9.8epss

    MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners…

  • CVE-2026-85430CriSep 3, 2026
    risk 0.52cvss 9.1epss

    MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject…

  • CVE-2026-85427HigSep 3, 2026
    risk 0.46cvss 8.1epss

    MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publish a mission file containing malicious Run…

  • CVE-2026-85436HigSep 3, 2026
    risk 0.42cvss 7.5epss

    MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can send crafted UDP packets to the configured…

  • CVE-2026-85431HigSep 3, 2026
    risk 0.42cvss 7.5epss

    MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with…