← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2020-08.md
Imported-content SHA-256
afc14b7dfce21d1ba85fe28b8c6e121c302f8aae463f2fd547022454adcaf1d6
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 August 2020 |
| Platform | Quiet Systems |
| Series | DKSR-M-2020-08 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Two control-path cases: Synacktiv’s enterprise Pilot analysis (same forced-update class as GO 4) and ZDI’s unauthenticated root overflow on Microhard Bullet-LTE.

### Key judgments

1. **[Assessment — High confidence]** Pilot writeup 4 August 2020. DJI disputed Weibo/“misleading.”
2. **[Assessment — High confidence]** ZDI-20-1206 / CVE-2020-17407 public 26 August 2020; fixed in R112.
3. **[Uncertainty]** How widely Bullet-LTE is flown vs industrial use.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Synacktiv: DJI Pilot enterprise forced update

*Event / publication dates: 4 August 2020*

| Field | Value |
| --- | --- |
| Component | software |
| Product | DJI Pilot Android (Matrice, Phantom 4, Mavic Pro, Mavic 2 Enterprise). Samples v1.8.0 / v1.7.2 |
| CVE / advisory | no CVE |
| Patch | disputed / partial |
| Exploit status | public writeup |
| Taxonomy | CAPEC-186 · ATT&CK ICS T0843 · OWASP IoT I3 · I4 · EMB3D TID-211 |

**Verified record — [Fact — A1] https://www.synacktiv.com/en/publications/dji-pilot-android-application-security-analysis-1.html**

**Exposure.** Enterprise GCS on the same update-trust failure as consumer GO 4. Local Data Mode still needs network for fly-zone unlock certs (account-linked).

**Intelligence assessment.** [Assessment — High confidence] Publication and product. [Uncertainty] Weibo residual (DJI denial vs website-build finding).

**Opportunity.** Passport Pilot separately from GO 4. Watch Local Data Mode’s remaining network dependency.

**LRRK relevance.** Control Fabric.

**Confidence.** High on date. Moderate on residual Weibo.
## 02. ZDI-20-1206: Microhard Bullet-LTE unauthenticated overflow

*Event / publication dates: 26 August 2020 (ZDI). NVD CVE-2020-17407 on 13 October 2020 not used for dating.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Microhard Bullet-LTE prior to v1.2.0-r1112 |
| CVE / advisory | CVE-2020-17407; ZDI-20-1206; ZDI-CAN-10596 |
| Patch | available — R112 |
| Exploit status | advisory-only / catalogued |
| Taxonomy | CWE-120 (class) · ATT&CK ICS T0860 · T0814 · OWASP IoT I2 |

**Verified record — [Fact — A1] https://www.zerodayinitiative.com/advisories/ZDI-20-1206/ · https://nvd.nist.gov/vuln/detail/CVE-2020-17407**

**Exposure.** Unauthenticated stack overflow on the UAV-marketed LTE bearer. Same family as ZSL-2018-5479.

**Intelligence assessment.** [Assessment — High confidence] Date, CVE, patch version. [Uncertainty] Fleet mix.

**Opportunity.** Passport Bullet-LTE ≥ R112. Pair with the 2018 authenticated-RCE case.

**LRRK relevance.** Control Fabric. Kestrel Microhard.

**Confidence.** High on ZDI/CVE. Moderate on how widely it is flown.

## Forward indicators

1. NVD catalogue of 17407 (October 2020) — index only.
2. Later Microhard CVE reprints (2025) — index only.

> **Collection integrity.** Two verified items. CWE-120 on ZDI is class (NVD CWE not re-fetched). No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>