LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 30 September 2021 | | Platform | Quiet Systems | | Series | DKSR-M-2021-09 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF River Loop could not verify that the 2020 GO 4 forced-update path was closed. REQUEST_INSTALL_PACKAGES and a custom update path were still there. ### Key judgments 1. **[Assessment — High confidence]** Blog 2 September 2021. Residual-status note, not a new CVE-class bug. 2. **[Assessment — Moderate confidence]** This contradicts a clean reading of DJI’s 31 July 2020 statement. 3. **[Inference — Moderate confidence]** Phone-side installer remains a live Passport field into 2021. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. River Loop: DJI GO 4 custom install path still present *Event / publication dates: 2 September 2021* | Field | Value | | --- | --- | | Component | software | | Product | then-current DJI GO 4 Android | | CVE / advisory | no CVE | | Patch | disputed / incomplete relative to the 31 July 2020 DJI statement | | Exploit status | public writeup | | Taxonomy | CAPEC-186 · ATT&CK ICS T0843 · OWASP IoT I4 · EMB3D TID-211 | **Verified record — [Fact — A1] https://riverloopsecurity.com/blog/2021/09/dji-go-updates/** **Exposure.** GCS/app update trust still not store-only. **Intelligence assessment.** [Assessment — High confidence] Date. [Uncertainty] Not a new defect class — residual of 2020-07. **Opportunity.** Keep GO 4 installer state on Watch until Play-only is evidenced. **LRRK relevance.** Control Fabric. **Confidence.** High on date. Moderate that this is residual, not new. ## Forward indicators 1. Play Store delisting of GO 4 (later coverage, 2021 — not independently re-dated here). > **Collection integrity.** Follow-up, not a new CVE. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>