# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Special filing: ten-year precedent, payload, peripheral, and power.

| Field | Value |
| --- | --- |
| Collection cutoff | 19 August 2026 |
| Platform | Quiet Systems |
| Series | DKSR-R-04 · Payload, peripheral, power (2016–2026) |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective special, not the daily 48-hour watch. Image rights require separate verification before publication. |

## Executive read

### BLUF

The airframe is not the only trust object. Cloud keys, a camera heartbeat on a naval USV, a shared media-transfer SDK, civil GPS, and a smart-battery CAN driver all sat on the kinematic path and failed in public.

### Key judgments

1. **[Assessment — High confidence]** DJI’s 2017 cloud-key exposure was the first widely reported proof that the dominant OEM’s customer-data / pairing boundary had failed, not just the aircraft radio.
2. **[Assessment — High confidence]** The August 2026 Kraken K3 Scout camera heartbeat is the first widely reported case of a payload module on a naval USV talking out of band. NDAA-label was not a firmware-behavior audit.
3. **[Inference — Moderate confidence]** Shared on-vehicle SDK services (QuickTransfer / `v2_sdk`) and optional BMS drivers will keep producing fleet-wide CVEs because one library or one CAN module ships on many SKUs.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. 2017 DJI cloud pairing: SSL, AWS, and firmware keys in public view

*Event / publication dates: researcher contact September 2017; public writeup 16 November 2017.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | DJI cloud / AWS S3 / wildcard web certificate / firmware AES material. Not a single airframe version. |
| CVE / advisory | no CVE |
| Patch | partial. DJI revoked the HTTPS certificate and obtained a new one (September 2017, per contemporary press). Full historical exposure window not independently measured. |
| Exploit status | public writeup. Not KEV. |
| Taxonomy | CAPEC-37 · ATT&CK Enterprise T1552 · OWASP IoT I3 |

**Verified record — [Fact — A1/B2]** Kevin Finisterre, “Why I walked away from $30,000 of DJI bounty money,” 16 November 2017 (PDF via The Register). Ars Technica, The Register, and BBC News the same week: private SSL, AWS, and firmware keys left on GitHub; researcher described seeing unencrypted flight logs and government ID images, including .mil/.gov-associated logs. DJI’s first public bug-bounty process collapsed into a CFAA-tinged dispute and then public terms.

**Exposure.** Cloud pairing and customer-data boundary. Logs and identity documents are Sense about the operator and the aircraft. Firmware keys feed the update path (see DKSR-R-03).

**Intelligence assessment.** [Assessment — High confidence] First widely reported OEM cloud-pairing failure in this window. [Assessment — High confidence] It remains the citation next to the August 2017 Army halt and Local Data Mode. [Uncertainty] How long keys were public and what was actually retrieved by third parties is not independently measured.

**Opportunity.** Passport cloud endpoints and key-material handling separately from airframe firmware. Do not treat Local Data Mode as a retrospective fix for 2017 cloud keys.

**LRRK relevance.** Control Fabric and Passport. Watch any later “2017 DJI data breach” claim and require this primary, not a gloss.

**Confidence.** High on the facts that were published. Medium on the unmeasured exposure window.

## 02. Kraken K3 Scout cameras: heartbeat to a China IP

*Event / publication dates: public reporting 10 August 2026 (BBC). MoD: found in a “routine cyber vulnerability assessment.” Assessment calendar date unpublished.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Kraken Technology Group K3 Scout USV (about 20 boats, RN / Operation Beehive). Cameras: unnamed third party, described by Kraken as “NDAA compliant” with “a small number of components originating from outside the UK.” Camera OEM, firmware rev, and IP not published. |
| CVE / advisory | no CVE |
| Patch | partial / unpublished. Kraken: “any potential vulnerabilities have been identified and closed.” Secondary reports: internet removed from affected cameras. MoD did not confirm or deny the connectivity cut. |
| Exploit status | none public. MoD: “no evidence of MoD data or systems being accessed, compromised or transmitted externally.” BBC: a squark *can* carry location — not stated that this one did. |
| Taxonomy | ATT&CK ICS T0862 · OWASP IoT I3 · I5 |

**Verified record — [Fact — A1/B2]** BBC, 10 August 2026; *The Independent*; *Naval Technology*; BetaNews. Third-party cameras on Royal Navy K3 Scout USVs sent heartbeat/squark traffic to a China IP. MoD found it in a routine cyber assessment and said there was no evidence of MoD data or systems accessed or transmitted externally.

**Exposure.** Payload egress on a naval USV. Sense (camera) with an undeclared Control Fabric channel. NDAA-compliant label did not bound firmware behavior.

**Intelligence assessment.** [Assessment — High confidence] First widely reported naval-USV camera out-of-band case. [Uncertainty] Camera OEM, exact IP, whether location left the boat, and whether MoD cut connectivity remain unpublished. [Inference — Moderate confidence] “NDAA compliant” will keep being treated as a Passport it is not.

**Opportunity.** Lab egress-deny on payload modules. Passport camera firmware behavior, not the NDAA sticker. Watch for a CVE or vendor name.

**LRRK relevance.** Sense and Control Fabric. Kestrel identical camera modules across the Registry. This is the live Watch item of the special series.

**Confidence.** High on the event and MoD quotes. Low on OEM, payload, and location-exfil.

## 03. Nozomi 2024: QuickTransfer and shared `v2_sdk` across Mavic and Matrice

*Event / publication dates: Nozomi advisories 29 March 2024; NVD 2 April 2024.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Mavic 3 Pro < 01.01.0300; Mavic 3 < 01.00.1200; Mavic 3 Classic < 01.00.0500; Mavic 3 Enterprise < 07.01.10.03; Matrice 300 < 57.00.01.00; Matrice M30 < 07.01.0022; Mini 3 Pro < 01.00.0620. Shared `libv2_sdk.so` / `dji_vtwo_sdk`, port 10000. |
| CVE / advisory | CVE-2023-6951 (weak Wi-Fi PSK); CVE-2023-51454 (OOB write); CVE-2023-51455 (array-index; GHSA-h647-j39p-3c46); CVE-2023-51456 (input validation). Related CVE-2023-6949 (unauthenticated media HTTP) **disputed** by DJI. |
| Patch | available (“upgrade to latest firmware,” Nozomi). 6949 disputed, not separately patched as a vuln. |
| Exploit status | advisory-only. CISA SSVC on 6951: exploitation none. Not KEV. |
| Taxonomy | CWE-334 (CNA) · CWE-129 (CNA, 51455) · CAPEC-115 · ATT&CK ICS T0860 · OWASP IoT I1 · I2 |

**Verified record — [Fact — A1]** Nozomi Labs advisories dated 29 March 2024 and the Mavic 3 research blog. NVD pages for CVE-2023-6951 / 51454 / 51455 / 51456. QuickTransfer is the payload-egress (photos/video) path. Fleet includes enterprise Matrice 300 and M30.

**Exposure.** Weak credentials plus memory-safety bugs in a shared on-drone SDK service. One library, many products, including enterprise.

**Intelligence assessment.** [Assessment — High confidence] Cleanest modern example that SDK/firmware commonality beats per-airframe hardening. [Uncertainty] Do not treat disputed CVE-2023-6949 as confirmed. [Inference — Moderate confidence] Other OEM “quick transfer” Wi-Fi APs deserve the same Passport field.

**Opportunity.** Passport shared-library hashes across Mavic/Matrice. Watch disputed 6949 if a third party reproduces it.

**LRRK relevance.** Control Fabric and Kestrel. Payload egress sits in Sense.

**Confidence.** High.

## 04. Sathaye et al. 2022: COTS DJI and Autel remain GPS-spoofable

*Event / publication dates: USENIX Security ’22, August 2022 (Boston).*

| Field | Value |
| --- | --- |
| Component | hardware |
| Product | COTS DJI and Autel UAVs (chamber OTA). No specific firmware CVE. |
| CVE / advisory | no CVE (civil GNSS property, not a software defect) |
| Patch | none at the receiver protocol layer. Later product-level mitigations (Galileo OSNMA operational 24 July 2025; u-blox firmware support) are not a fix for this paper. |
| Exploit status | public writeup. Implementation released to researchers. Not KEV. |
| Taxonomy | CWE-345 (class) · CAPEC-148 · OWASP IoT I7 |

**Verified record — [Fact — A1]** Sathaye, Schepers, Ranganathan, *An Experimental Study of GPS Spoofing and Takeover Attacks on UAVs*, USENIX Security 2022. Chamber OTA on COTS DJI and Autel. Paper: COTS UAVs remain spoofable; precise takeover needs real-time, fine-grained spoofing.

**Exposure.** Unauthenticated civil GPS is navigation-state capture. Sense collapses Move. Humphreys 2012 / Kerns 2014 are the pre-window citations; this is the in-window stack update.

**Intelligence assessment.** [Assessment — High confidence] Standard in-window citation for UAV GPS-spoof takeover on current DJI/Autel. [Inference — Moderate confidence] OSNMA and similar will appear in Passports as mitigations, not as proof the class is closed.

**Opportunity.** Passport GNSS authentication (OSNMA/other) as a field, evidenced, not brochure. Lab takeover vs nuisance spoof as different claims.

**LRRK relevance.** Sense-Move-Act. KAT from RF to navigation state to actuator.

**Confidence.** High.

## 05. CVE-2026-32707: Tattu smart-battery CAN can crash PX4

*Event / publication dates: GHSA 13 March 2026; NVD 16 March 2026.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | PX4-Autopilot ≤ 1.17.0-rc1 with `CONFIG_DRIVERS_TATTU_CAN` + `tattu_can start`. GHSA: typically vendor/custom firmware; not commonly enabled in default upstream builds. Tattu 12S smart-battery path. |
| CVE / advisory | CVE-2026-32707; GHSA-wxwm-xmx9-hr32 |
| Patch | available. 1.17.0-rc2, or disable `tattu_can` |
| Exploit status | public writeup. CISA-ADP SSVC: exploitation poc. Requires CAN injection (AV:P). Not KEV. |
| Taxonomy | CWE-121 (GHSA) · ATT&CK ICS T0814 · OWASP IoT I5 |

**Verified record — [Fact — A1]** PX4 GHSA-wxwm-xmx9-hr32 and NVD CVE-2026-32707: unbounded memcpy in Tattu smart-battery CAN reassembly. Fixed in 1.17.0-rc2. Advisory demonstrates crash / memory corruption. It does **not** demonstrate an in-flight vehicle drop. Secondary write-ups that infer loss of control are not treated as proven.

**Exposure.** Powertrain / BMS on the flight CAN. Closest in-window “BMS that can drop a vehicle,” still physical-CAN and module-optional.

**Intelligence assessment.** [Assessment — High confidence] First published CVE where a smart-battery driver on the flight CAN can crash the autopilot. [Uncertainty] Field drop is unproven. [Inference — Moderate confidence] Other vendor CAN-BMS modules deserve the same Watch even without a CVE.

**Opportunity.** Passport `tattu_can` enabled and PX4 ≥ 1.17.0-rc2. Lab CAN-BMS as a trust path, not a battery.

**LRRK relevance.** Control Fabric on power. Sense (BMS telemetry) to Act (FC crash).

**Confidence.** High on the CVE. Low on “drops a vehicle in the field.”

## Forward indicators

1. Camera OEM, firmware, and IP for the K3 Scout case, or a CVE.
2. A second naval / government USV or UUV payload-egress case with a named module.
3. Autel vendor advisory for CVE-2023-47335 (NFZ) — still missing; kept off this filing as single-source GEO.
4. A published UAV citation for a u-blox, OpenIPC, ESC, or dock-update CVE (none met the bar in this window).
5. Independent BDA that tattu_can corruption produces loss of control in flight, which the advisory does not claim.

> **Collection integrity.** NVD, GHSA, USENIX, BBC/MoD quotes, Finisterre/Ars/Register/BBC 2017, Nozomi 2024. No KEV. Searched and not found as public UAV/ROV-impact CVEs: Blue Robotics, VideoRay, Saab Seaeye, QYSEA, Greensea; dedicated ESC-drop CVE; dock/nest update CVE; u-blox GNSS CVE cited for UAV nav; OpenIPC; SiK/RFD900; Microhard pMDDL; Crossfire/TBS. Generic Jetson/ESP32/STM32 CVEs exist; none checked had a published UAV citation that was more than “it could.” FLIR AX8/PT/M300 camera CVEs were not treated as air payloads without a primary that says so. Parrot ANAFI 2019 (CVE-2019-3944/45) and ANAFI USA (CVE-2024-33844) are clean OEM disclosures and are listed in the canon, not duplicated here. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
