VYPR

Px4 Autopilot

by Px4

Source repositories

CVEs (30)

  • CVE-2026-32724MedMar 16, 2026
    risk 0.27cvss 5.3epss 0.00

    PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receiver thread (which handles shell creation/destruction) and the…

  • CVE-2026-32707MedMar 16, 2026
    risk 0.27cvss 5.2epss 0.00

    PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN frames are processed. In deployments where tattu_can is enabled and running, a…

  • CVE-2024-24255MedFeb 6, 2024
    risk 0.27cvss 4.2epss 0.00

    A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.

  • CVE-2024-24254MedFeb 6, 2024
    risk 0.27cvss 4.2epss 0.00

    PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes.

  • CVE-2025-5640LowJun 5, 2025
    risk 0.25cvss 3.3epss 0.01

    A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the file mavlink_receiver.cpp of the component TRAJECTORY_REPRESENTATION_WAYPOINTS Message…

  • CVE-2026-32713MedMar 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and WriteFile operations to proceed with invalid sessions or…

  • CVE-2025-15150MedDec 28, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer…

  • CVE-2024-30800MedApr 23, 2024
    risk 0.00cvss 5.6epss 0.00

    PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

  • CVE-2023-47625LowNov 13, 2023
    risk 0.00cvss 2.9epss 0.01

    PX4 autopilot is a flight control solution for drones. In affected versions a global buffer overflow vulnerability exists in the CrsfParser_TryParseCrsfPacket function in /src/drivers/rc/crsf_rc/CrsfParser.cpp:298 due to the invalid size check. A malicious user may create an RC…

  • CVE-2021-34125HigMar 9, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.

Page 2 of 2