Junglewise Threat Intelligence

CVE-2026-83772: Cobham SATCOM VSAT7090 command injection in JSON parsing

CVE-2026-83772 · Severity: critical · CVSS 9.9 · Published 2026-09-01

Executive brief

The Cobham SATCOM VSAT7090 is a maritime satellite router used for communications on vessels and remote locations. A command injection vulnerability in its JSON parsing component allows remote attackers to execute arbitrary commands by manipulating sender/recipient fields, potentially compromising router operations, intercepting communications, or using the device as a foothold into maritime networks.

Technical details

The vulnerability is a command injection flaw in the c_set_reports_decode function of the mail-report.sh component's JSON parsing logic. By injecting malicious commands through the sender or recipients argument fields, an unauthenticated remote attacker can execute arbitrary system commands on the router. The attack requires network access to the router but does not require prior authentication or user interaction. Successful exploitation grants command-level access to the device, enabling full compromise of the satellite router's functionality and data. No patch has been released as the vendor did not respond to early disclosure notification.

Affected products

  • Cobham SATCOM VSAT7090 up to 20260704

Timeline

  • 2026-09-01: disclosed
  • exploited: exploit made public

References