# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 December 2025 |
| Platform | Quiet Systems |
| Series | DKSR-M-2025-12 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

FCC puts foreign-produced UAS and UAS critical components on the Covered List. That is an authorization bar, not a software CVE. DJI and Autel are named in the cited statute.

### Key judgments

1. **[Assessment — High confidence]** DA-25-1086 / 22 December 2025. Going-forward equipment authorizations barred.
2. **[Assessment — High confidence]** Existing authorizations were not automatically revoked by the 22 December entry.
3. **[Inference — Moderate confidence]** Patch access and update-trust paths change when radios cannot be newly authorized.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. FCC Covered List: foreign UAS and critical components

*Event / publication dates: 22 December 2025 (FCC Public Notice / Fact Sheet)*

| Field | Value |
| --- | --- |
| Component | dependency |
| Product | Foreign-produced UAS and UAS critical components; FY25 NDAA §1709(a)(1) names DJI and Autel Robotics |
| CVE / advisory | FCC Covered List update; DA-25-1086 |
| Patch | not applicable |
| Exploit status | not applicable |
| Taxonomy | ATT&CK ICS T0862 |

**Verified record — [Fact — A1] https://www.fcc.gov/document/fcc-updates-covered-list-add-certain-uas-and-uas-components-0 · https://docs.fcc.gov/public/attachments/DA-25-1086A1.txt**

**Exposure.** New FCC equipment authorizations barred. Hardware and radio access, not a firmware ID.

**Intelligence assessment.** [Assessment — High confidence] Policy case that changes update and import trust. [Uncertainty] How existing authorized fleet is treated later is not this notice.

**Opportunity.** Watch next-year vendor-commissioned audits (OnDefend, May 2026) as responses, not rebuttals of a CVE.

**LRRK relevance.** Watch and Campaign (authorization). Not Lab.

**Confidence.** High.

## Forward indicators

1. OnDefend assessment publication (May 2026).
2. Any revocation of *existing* authorizations (not claimed here).

> **Collection integrity.** Policy, included because it changes patch/import access. No CVE invented. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
