Executive brief
The Cobham SATCOM VSAT7090 is a maritime satellite router used for communications on vessels and remote locations. A command injection vulnerability in its JSON parsing component allows remote attackers to execute arbitrary commands by manipulating sender/recipient fields, potentially compromising router operations, intercepting communications, or using the device as a foothold into maritime networks.
Technical details
The vulnerability is a command injection flaw in the c_set_reports_decode function of the mail-report.sh component's JSON parsing logic. By injecting malicious commands through the sender or recipients argument fields, an unauthenticated remote attacker can execute arbitrary system commands on the router. The attack requires network access to the router but does not require prior authentication or user interaction. Successful exploitation grants command-level access to the device, enabling full compromise of the satellite router's functionality and data. No patch has been released as the vendor did not respond to early disclosure notification.
Affected products
- Cobham SATCOM VSAT7090 up to 20260704
Timeline
- 2026-09-01: disclosed
- exploited: exploit made public