← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/specials/dksr-03-update-filesystem.md
Imported-content SHA-256
c96551707180ccfc7c5f2e7e26808891fe1b55be1f00d0c9329484e97ba12a15
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Special filing: ten-year precedent, update path and filesystem.

| Field | Value |
| --- | --- |
| Collection cutoff | 19 August 2026 |
| Platform | Quiet Systems |
| Series | DKSR-R-03 · Update and filesystem (2016–2026) |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective special, not the daily 48-hour watch. Image rights require separate verification before publication. |

## Executive read

### BLUF

Signed firmware was the story. The decade’s record is that the update channel, the phone-side installer, and the MAVLink filesystem were the actual trust boundaries, and they failed in public.

### Key judgments

1. **[Assessment — High confidence]** DJI’s 2017 DUML / RedHerring work showed that asymmetric firmware signing and the Assistant update path were not a hard boundary on flying products.
2. **[Assessment — High confidence]** PX4’s 2026 MAVLink FTP CVE shows the same class on the open stack: an unauthenticated C2 peer can rewrite the flight-controller filesystem.
3. **[Inference — Moderate confidence]** Phone-side forced update (DJI GO 4, 2020) will keep mattering wherever GEO/NFZ and safety patches are delivered outside a store review path.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. 2017 DUML / RedHerring: signed DJI firmware was bypassable

*Event / publication dates: Freek van Tienen key publications 27 June 2017; RedHerring public 6 July 2017; press and repo notes later that year.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | DJI Phantom 4, Inspire 2, Mavic Pro, Spark (and related RC/goggles). Repo notes: Spark aircraft FW V01.00.0500 and Mavic V01.03.1000 addressed the original FTPD/tar variant. |
| CVE / advisory | no CVE |
| Patch | partial. Busybox/FTPD and “ro” filesystem mitigations shipped; PUEK/PRAK/RREK key rotation continued into 2018–2025 (PUEK-2017-09 republished 4 November 2025 by Kookmin Univ. / KAERI, as a key-comment commit, not a new CVE). |
| Exploit status | public writeup (o-gs tools, MAVProxyUser/P0VsRedHerring, DUMLdore). Not KEV. |
| Taxonomy | CAPEC-186 · ATT&CK ICS T0839 · T0843 · OWASP IoT I4 · EMB3D TID-211 · TID-213 |

**Verified record — [Fact — A1/B2]** Public 2017 research (o-gs/dji-firmware-tools; MAVProxyUser/P0VsRedHerring; Motherboard/Vice; CyberScoop bounty coverage) showed extracted firmware crypto keys and a DUML/FTPD path that defeated signed updates and yielded root / policy bypass on Spark and Mavic. NDSS 2023 later confirmed leaked keys still decrypted firmware modules.

**Exposure.** Update trust and filesystem trust on the dominant OEM. GEO/altitude/distance policy sat behind that boundary.

**Intelligence assessment.** [Assessment — High confidence] First widely copied demonstration that DJI signing plus Assistant/DUML was not a hard boundary. [Assessment — High confidence] It is the technical ancestor of the 2023 NDSS signing-bypass finding. [Uncertainty] Exact patched-version completeness is forum/GitHub, not a formal vendor advisory.

**Opportunity.** Passport firmware-key generation, not “signed = trusted.” Kestrel key-rotation events separately from the extraction class.

**LRRK relevance.** Control Fabric and Lab. Campaign unofficial firmware as evidence that the Passport failed, not as a how-to.

**Confidence.** High on existence and product impact. Moderate on patch completeness.

## 02. DJI GO 4 (2020): the phone is the update path

*Event / publication dates: Synacktiv / GRIMM public analysis July 2020; DJI statement the same month.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | DJI GO 4 Android — versions cited by Synacktiv include V4.1.22 (December 2017), V4.3.25 (9 October 2019), v4.3.36_200426 (12 May 2020). Pilot enterprise app also analyzed; vendor disputed later Pilot claims. |
| CVE / advisory | no CVE |
| Patch | partial / disputed. DJI said it removed a collecting SDK and began routing safety updates to Play Store; it called the forced-update path a safety feature against “hacked” GEO/altitude-limit bypass apps. |
| Exploit status | public writeup. Not KEV. |
| Taxonomy | CAPEC-186 · ATT&CK ICS T0843 · OWASP IoT I3 · I4 · EMB3D TID-211 |

**Verified record — [Fact — A1/B2]** Synacktiv, “DJI Android GO 4 application security analysis,” and GRIMM, “DJI Privacy Analysis Validation,” documented a Play Store–bypassing forced APK path and identifier-collecting SDKs. CyberScoop (23 July 2020) and DroneLife (29 July 2020) carried the DJI statement. SecurityWeek recorded DJI calling later Pilot claims “misleading.” GO 4 was later delisted from Play Store (2021), as reported in subsequent coverage.

**Exposure.** A million-plus-install pairing and GEO/NFZ channel that can install code outside store review.

**Intelligence assessment.** [Assessment — High confidence] First high-visibility proof that the phone-side update path is a kinematic trust path. [Uncertainty] Pilot enterprise behavior remains vendor-disputed. [Inference — Moderate confidence] Local Data Mode does not close a forced-update path that lives on the phone.

**Opportunity.** Passport the installer (store vs sideload vs in-app). Watch enterprise Pilot separately from GO 4.

**LRRK relevance.** Control Fabric. Sense (who is on the phone) to Act (what firmware policy the aircraft obeys).

**Confidence.** High on GO 4. Moderate on Pilot.

## 03. CVE-2020-29664: Mavic 2 RC firmware-upgrade handler

*Event / publication dates: NVD 18 February 2021.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | DJI Mavic 2 Remote Controller firmware before 01.00.0510 |
| CVE / advisory | CVE-2020-29664 (NVD High, AV:L) |
| Patch | available. Firmware 01.00.0510+ |
| Exploit status | public writeup (NVD refs include third-party write-ups tagged Exploit). Local/privileged vector per NVD. Not KEV. |
| Taxonomy | CWE-78 (class) · ATT&CK ICS T0843 · OWASP IoT I4 · EMB3D TID-211 |

**Verified record — [Fact — A1]** NVD CVE-2020-29664 records command injection in `dji_sys` via a firmware-upgrade packet on the Mavic 2 RC before 01.00.0510, fixed in 01.00.0510 and later.

**Exposure.** The controller, not the airframe, is on the kinematic chain. An update-path injection on the RC is still Control Fabric.

**Intelligence assessment.** [Assessment — High confidence] Clean assigned-CVE example of a GCS/RC update-path failure. [Inference — Moderate confidence] RC and goggles deserve their own Passports; they are not “the drone.”

**Opportunity.** Inventory RC/goggle firmware independently of aircraft FW.

**LRRK relevance.** Control Fabric. Lab the update handler as a separate object.

**Confidence.** High.

## 04. CVE-2026-32709: unauthenticated MAVLink FTP is the FC filesystem

*Event / publication dates: GHSA 13 March 2026; NVD 16 March 2026.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | PX4 Autopilot prior to 1.17.0-rc2 (NuttX flight controller and POSIX companion/SITL) |
| CVE / advisory | CVE-2026-32709; GHSA-fh32-qxj9-x32f |
| Patch | available. 1.17.0-rc2 |
| Exploit status | public writeup (GHSA). Needs a MAVLink peer. Not KEV. |
| Taxonomy | CWE-22 (GHSA) · CAPEC-126 · ATT&CK ICS T0836 · T0889 · OWASP IoT I2 · EMB3D TID-406 |

**Verified record — [Fact — A1]** PX4 GHSA-fh32-qxj9-x32f and NVD CVE-2026-32709 describe path traversal in MAVLink FTP with an empty FTP root and no authentication, allowing arbitrary file read/write/create/delete/rename. Advisory scope includes params, logs, keys, missions, geofences. Fixed in 1.17.0-rc2.

**Exposure.** Persistence on the flight controller: change behavior or brick the controller. Complements CVE-2026-1579 (commands/shell) with filesystem write.

**Intelligence assessment.** [Assessment — High confidence] First clean CVE that a normal MAVLink peer can rewrite the FC filesystem. [Inference — Moderate confidence] Any integrator still on ≤ 1.17.0-rc1 with FTP enabled inherits this.

**Opportunity.** Passport MAVLink FTP enabled/disabled and root path. Patch evidence is the rc2 tag, not “we use MAVLink 2.”

**LRRK relevance.** Control Fabric and Lab. Campaign FTP-on as a Watch item across PX4 ports.

**Confidence.** High.

## 05. CVE-2024-40427: SERIAL_CONTROL is also memory-unsafe

*Event / publication dates: GHSA 3 July 2024; CVE 7 January 2025.*

| Field | Value |
| --- | --- |
| Component | software |
| Product | PX4-Autopilot; NVD CPE up to (excluding) 1.14.3; commit e03e026. OSV/Snyk version bounds disagree (1.14.3 vs 1.16.0-alpha1). |
| CVE / advisory | CVE-2024-40427; GHSA-55wq-2hgm-75m4 |
| Patch | commit e03e0261a1a0c82f545e66a1e3795956c886db71. Treat “which release first contains it” as unverified. |
| Exploit status | public writeup (GHSA). CISA SSVC exploitation: poc. Not KEV. |
| Taxonomy | CWE-120 (ADP) · ATT&CK ICS T0814 · OWASP IoT I2 |

**Verified record — [Fact — A1]** PX4 GHSA-55wq-2hgm-75m4 records a stack buffer overflow in `handle_message_serial_control` from an unchecked length field. NVD published CVE-2024-40427 on 7 January 2025. This opens the later SERIAL_CONTROL cluster (UAF CVE-2025-9020 / CVE-2026-32724; ArduPilot OOB CVE-2026-38971).

**Exposure.** The same message that CISA later treats as an unauthenticated shell is also memory-unsafe. Physical: MAVLink task crash / loss of C2.

**Intelligence assessment.** [Assessment — High confidence] First CVE that the shell/passthrough message is not only unauthenticated but memory-unsafe. [Uncertainty] Fixed-release mismatch between NVD and OSV/Snyk. [Uncertainty] CVE-2026-32724 and CVE-2025-9020 look overlapping; do not merge here.

**Opportunity.** One Passport field for SERIAL_CONTROL: auth state and memory-safety patch level.

**LRRK relevance.** Control Fabric. Watch the 2025–2026 SERIAL_CONTROL cluster as one campaign, not five CVEs.

**Confidence.** High on the bug class. Medium on exact fixed release.

## Forward indicators

1. A formal DJI advisory that maps 2017 DUML/key issues to versions (still absent).
2. First tagged PX4 release that is unambiguous for CVE-2024-40427.
3. QGC GHSA-v5rc gaining a CVE and a demonstrated vehicle-moving impact (currently the nearest miss).
4. ArduPilot CVE-2026-38971 fixed-release clarification (through 4.6.3 vs after 4.6.3).
5. Enterprise Pilot forced-update behavior documented by a party other than the vendor.

> **Collection integrity.** NVD, GHSA, Synacktiv, GRIMM, o-gs/GitHub, NDSS cross-check. No KEV. PUEK-2017-09 2025 republication is a key-comment commit, not a new CVE. Autel EVO Nano NFZ (CVE-2023-47335) is a GEO/authorization case, not an update-path case, and is held for a later GEO note (single-source, no vendor advisory). No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>