Executive brief
MOOS essential-moos is a middleware platform for underwater robotics and distributed communications systems. A buffer overflow vulnerability in its UDP networking component allows remote attackers to send specially crafted network packets that corrupt memory and crash the application, disrupting mission-critical marine operations.
Technical details
The vulnerability is a classic buffer overflow in the CMOOSUDPLink::ReadPktFromArray() method, triggered by negative or oversized length fields in incoming UDP datagrams. When processing a crafted packet, the code performs an unchecked memcpy() operation that writes beyond the allocated buffer boundary, corrupting the heap. The attack requires network connectivity to the configured UDPListen port and no authentication; a remote attacker can trigger denial of service or potentially achieve code execution via heap corruption. The vulnerability affects essential-moos versions up to and including 10.0.1.
Affected products
- MOOS essential-moos through 10.0.1
Timeline
- 2026-09-03: disclosed