Executive brief
MOOS-IvP is an autonomous marine vehicle robotics framework. The uFldShoreBroker component, used to bridge communication between nodes, fails to verify that node ping messages are authentic. An attacker can send forged ping messages to redirect bridged data streams to attacker-controlled destinations, compromising data integrity and potentially enabling command injection on connected autonomous systems.
Technical details
The vulnerability is an authentication bypass in uFldShoreBroker's handling of NODE_BROKER_PING messages. The broker creates outbound bridge routes based on HostRecord data in these pings without verifying the sender's identity or the message authenticity. An unauthenticated network attacker can craft and publish a NODE_BROKER_PING message with malicious HostRecord fields to redirect variables that should be bridged to one node toward an attacker-controlled address instead. No user interaction or prior authentication is required—the attack is triggered upon message receipt. This allows interception, manipulation, or poisoning of bridged data streams, potentially enabling command injection into autonomous vehicle systems.
Affected products
- MOOS-IvP MOOS-IvP through 24.8.1
Timeline
- 2026-09-03: disclosed