CVE-2026-85431
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| themoos | essential-moos | 0 <= 10.0.1 | affected |
Weaknesses
- CWE-345: Insufficient Verification of Data Authenticity
References
- https://github.com/themoos/essential-moos/pull/19
- https://github.com/themoos/essential-moos/commit/d8441eac57d04ee89e7b82723480d10a558b45d6
- https://github.com/themoos/essential-moos
- https://github.com/themoos/essential-moos/blob/b897ea86dba8b61412dc48ac0cfb5ff34cdaf5f6/Essentials/pMOOSBridge/MOOSUDPLink.cpp#L21
- https://www.vulncheck.com/advisories/moos-essential-moos-through-10.0.1-pmoosbridge-unauthenticated-udp-packet-injection
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.