LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 March 2021 | | Platform | Quiet Systems | | Series | DKSR-M-2021-03 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF PX4 #17062 is the only in-window Yuneec public case found: NuttX memory-debug commands left on can dump firmware and bypass readout protection. The CVE number is a 2023 catalogue. ### Key judgments 1. **[Assessment — High confidence]** Issue 9 March 2021. PR #17264 disables mb/mh/mw by default the same month. 2. **[Uncertainty]** Yuneec Mantis Q (later CVE text) vs Typhoon H (issue example). 3. **[Assessment — High confidence]** CVE-2021-34125 NVD 9 March 2023 is not this month. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. PX4 #17062: NuttX memory-debug firmware dump *Event / publication dates: 9 March 2021 (GitHub). CVE-2021-34125 NVD 9 March 2023 not used for dating.* | Field | Value | | --- | --- | | Component | firmware | | Product | PX4-Autopilot v1.11.3 and below (later CVE text); Yuneec Mantis Q / Typhoon H examples | | CVE / advisory | no CVE in 2021. Later CVE-2021-34125. PX4 #17062; PR #17264 | | Patch | available in PX4 (debug commands off by default). Yuneec product patch unverified | | Exploit status | public writeup. Later catalogued | | Taxonomy | OWASP IoT I9 | **Verified record — [Fact — A1] https://github.com/PX4/PX4-Autopilot/issues/17062 · https://nvd.nist.gov/vuln/detail/CVE-2021-34125** **Exposure.** Debug surface on the autopilot. Firmware confidentiality / IP-protection bypass, not a C2 inject. **Intelligence assessment.** [Assessment — High confidence] GitHub-first date and PX4 mitigation. [Uncertainty] Exact Yuneec SKU map. **Opportunity.** Passport NSH debug commands disabled. Do not back-date the 2023 CVE into 2023-03 as a new bug. **LRRK relevance.** Control Fabric (debug left on). Lab readout-protection as a separate claim. **Confidence.** High on PX4. Moderate on Yuneec SKU. ## Forward indicators 1. CVE-2021-34125 catalogue (March 2023) — index only. 2. Other OEM NuttX images that still ship mb/mh/mw. > **Collection integrity.** Only in-window Yuneec public case found. No Autel/Skydio/QGC CVE in 2018–2021. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>