Px4 Drone Autopilot
Dronecode · 23 CVEs
PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
Mar 18, 2026
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition
Mar 13, 2026
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors
Mar 13, 2026
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)
Mar 13, 2026
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)
Mar 13, 2026
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
Mar 13, 2026
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
Mar 13, 2026
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
Mar 13, 2026
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.…
Mar 10, 2026
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from…
Mar 10, 2026
PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow
Dec 28, 2025
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerabilit…
Jan 7, 2025
PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics…
Jun 25, 2024
A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink me…
Jun 25, 2024
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the…
Apr 23, 2024
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of ser…
Apr 22, 2024
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone v…
Apr 10, 2024
A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allow…
Feb 6, 2024
PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Cond…
Feb 6, 2024
Global Buffer Overflow leading to denial of service in PX4-Autopilot
Nov 13, 2023
PX4-Autopilot Heap Buffer Overflow Bug
Oct 31, 2023
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handl…
Jul 6, 2023
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive…
Mar 9, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-32743 | PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling | MEDIUM | 0.33% | Mar 18, 2026 |
| CVE-2026-32724 | PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition | MEDIUM | 0.23% | Mar 13, 2026 |
| CVE-2026-32713 | PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors | MEDIUM | 0.29% | Mar 13, 2026 |
| CVE-2026-32709 | PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete) | MEDIUM | 0.32% | Mar 13, 2026 |
| CVE-2026-32708 | Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot) | HIGH | 0.26% | Mar 13, 2026 |
| CVE-2026-32707 | PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop | MEDIUM | 0.27% | Mar 13, 2026 |
| CVE-2026-32706 | PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet | HIGH | 0.31% | Mar 13, 2026 |
| CVE-2026-32705 | PX4 autopilot BST Device Name Length Can Overflow Driver Buffer | MEDIUM | 0.28% | Mar 13, 2026 |
| CVE-2026-26742 | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-a… | HIGH | 0.29% | Mar 10, 2026 |
| CVE-2026-26741 | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone… | HIGH | 0.29% | Mar 10, 2026 |
| CVE-2025-15150 | PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow | MEDIUM | 0.25% | Dec 28, 2025 |
| CVE-2024-40427 | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to exe… | HIGH | 0.35% | Jan 7, 2025 |
| CVE-2024-38952 | PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp. | HIGH | 0.70% | Jun 25, 2024 |
| CVE-2024-38951 | A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message. | MEDIUM | 0.53% | Jun 25, 2024 |
| CVE-2024-30800 | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function. | MEDIUM | 0.21% | Apr 23, 2024 |
| CVE-2024-30799 | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point functio… | MEDIUM | 0.26% | Apr 22, 2024 |
| CVE-2024-29460 | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the missio… | MEDIUM | 0.24% | Apr 10, 2024 |
| CVE-2024-24255 | A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended… | MEDIUM | 0.34% | Feb 6, 2024 |
| CVE-2024-24254 | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp… | MEDIUM | 0.36% | Feb 6, 2024 |
| CVE-2023-47625 | Global Buffer Overflow leading to denial of service in PX4-Autopilot | MEDIUM | 0.52% | Nov 13, 2023 |
| CVE-2023-46256 | PX4-Autopilot Heap Buffer Overflow Bug | CRITICAL | 0.63% | Oct 31, 2023 |
| CVE-2021-46896 | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332. | HIGH | 0.81% | Jul 6, 2023 |
| CVE-2021-34125 | An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands. | HIGH | 0.96% | Mar 9, 2023 |
Showing 1 to 23 of 23 CVEs