← Terug naar overzicht

A critical command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router up to version 20260704. The vulnerability exists in the c_set_reports_decode function within the mail-report.sh file, specifically in the JSON Parsing component. Attackers can manipulate the sender/recipients arguments to inject arbitrary commands. The vulnerability is remotely exploitable, significantly increasing its risk profile. A public exploit is already available, making active exploitation a realistic threat. The vendor was notified prior to public disclosure but did not respond. This affects maritime satellite communication infrastructure, which is considered critical for naval and shipping operations. The lack of vendor response and availability of a public exploit elevate the urgency for mitigation.

Affected products

  • Cobham SATCOM VSAT7090 Maritime Satellite Router

Related CVE's

  • CVE-2026-83772

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities