← Terug naar overzicht

A critical command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router affecting versions up to 20260704. The vulnerability exists in the function c_set_reports_decode within the mail-report.sh file, specifically in the JSON Parsing component. Attackers can manipulate the sender/recipients arguments to achieve remote command injection. The attack can be launched remotely without physical access to the device. A public exploit is available and actively usable. The vendor was notified prior to disclosure but failed to respond. This vulnerability poses a significant risk to maritime satellite communication infrastructure. No patch or mitigation has been provided by the vendor.

Affected products

  • Cobham SATCOM VSAT7090 Maritime Satellite Router

Related CVE's

  • CVE-2026-83772

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure