LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Special filing: ten-year precedent, identity and detection. | Field | Value | | --- | --- | | Collection cutoff | 19 August 2026 | | Platform | Quiet Systems | | Series | DKSR-R-02 · Identity and detection (2016–2026) | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective special, not the daily 48-hour watch. Image rights require separate verification before publication. | ## Executive read ### BLUF Remote ID and AeroScope were sold as a closed trust boundary for operator and aircraft location. The decade’s record is that the broadcast is a plaintext sensor, and the receivers that treat it as truth inherit that property. ### Key judgments 1. **[Assessment — High confidence]** DJI DroneID / AeroScope (CVE-2022-29945) is the first assigned CVE that the market leader’s law-enforcement tracking channel was not encrypted, contrary to prior public statements. 2. **[Assessment — High confidence]** Commercial RID receivers (BlueMark DroneScout, 2023) can be made to prefer a spoofed Open Drone ID track and had an insecure firmware-update path. 3. **[Inference — Moderate confidence]** Detection stacks that ingest unauthenticated ASTM F3411 / OpenDroneID as a location source will keep failing the same way until the broadcast carries a verifiable identity. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. CVE-2022-29945: DJI DroneID / AeroScope in the clear *Event / publication dates: The Verge, 28 April 2022; NVD published 29 April 2022; Schiller et al., NDSS 2023 (27 February–3 March 2023).* | Field | Value | | --- | --- | | Component | firmware | | Product | DJI devices sold 2017–2022 listed by NVD (Air 2 / Air 2S, Phantom 4 Pro, FPV, Inspire 2, Mavic 3, Mini 2, Mini SE, RC Pro, Zenmuse X5S / X7). Precise firmware mapping unknown (NVD evaluator note). | | CVE / advisory | CVE-2022-29945 | | Patch | partial. Public reporting 2024: DJI added DroneID encryption plus a required AeroScope USB dongle. 2017–2022 fleet remains listed as affected. | | Exploit status | public writeup. Reported operational use of the broadcast (Ukraine/Russia targeting claims). Not KEV. | | Taxonomy | CWE-319 (NVD) · CAPEC-157 · ATT&CK ICS T0860 · OWASP IoT I7 | **Verified record — [Fact — A1]** NVD CVE-2022-29945 (29 April 2022) records unencrypted sensitive location in DJI DroneID. Sean Hollister, *The Verge* (28 April 2022): DJI had stated AeroScope signals were encrypted and then admitted they were not, after Kevin Finisterre challenged the claim. Schiller et al., “Drone Security and the Mysterious Case of DJI’s DroneID,” NDSS 2023, reconstructed the broadcast with a COTS SDR decoder. **Exposure.** Operator, home, and aircraft position on an RF channel anyone can receive. That is Sense about the operator, used as Act against the operator if the broadcast is treated as a targeting aid. **Intelligence assessment.** [Assessment — High confidence] First public proof the market-leader RID channel was not a closed trust boundary. [Assessment — Moderate confidence] Later wartime reporting describes use of the broadcast; that is not a CISA KEV listing and is not a catalogued exploit of the CVE. [Uncertainty] Exact firmware-to-SKU map is an NVD evaluator gap. **Opportunity.** Passport DroneID encryption state and AeroScope dongle requirement by airframe year. Watch remaining 2017–2022 fleet. **LRRK relevance.** Sense and Watch. Kestrel identical OcuSync/DroneID modules. Lab the broadcast as a sensor, not as a law-enforcement exclusive. **Confidence.** High on the CVE, the Verge correction, and the NDSS reconstruction. Moderate on 2024 encryption completeness for the whole fleet. ## 02. NDSS 2023: identity spoof, signing bypass, DUML bus *Event / publication dates: NDSS 2023, 27 February–3 March 2023 (DOI 10.14722/ndss.2023.24217).* | Field | Value | | --- | --- | | Component | firmware | | Product | Mini 2 (01.05.0000 / fuzzed 01.03.0000), Mavic Air 2 (01.01.0920 / 01.01.0610), Mavic 2 Pro (01.00.0770), Mavic 3 (01.00.0600), RC231/RC-N1 (04.11.0034), as published. | | CVE / advisory | no CVE found for the 16 items. Thematically overlaps CVE-2022-29945 (DroneID), a separate record. | | Patch | available (authors: “DJI has fixed all bugs”; signing bypass rated critical by DJI in disclosure). No public CVE-to-version map. | | Exploit status | public writeup (paper + open-sourced DroneID receiver). Not KEV. | | Taxonomy | CWE-319 (broadcast via CVE-2022-29945) · CAPEC-157 · ATT&CK ICS T0860 · OWASP IoT I7 · I4 · EMB3D TID-213 (signing-bypass half) | **Verified record — [Fact — A1]** Schiller, Chlosta, Schloegel, Bars, Eisenhofer, Scharnowski, Domke, Schönherr and Holz reported sixteen DJI firmware/protocol flaws, including an unsigned transceiver patch, serial spoof, and remote crash. Fourteen of sixteen were reachable via the phone/RC path. Authors say DJI fixed all reported bugs. NVD/paper/repo search found no CVE numbers for those sixteen. **Exposure.** Immutable identity, update signing, and the internal DUML bus all failed on modern OcuSync products. That is Control Fabric plus Sense (who the aircraft claims to be). **Intelligence assessment.** [Assessment — High confidence] First peer-reviewed full-stack proof that post-2017 OcuSync still failed signing, identity, and DUML as a trusted bus. [Uncertainty] Vendor-private IDs may exist and were never published. [Inference — Moderate confidence] The 2017 jailbreak line (RedHerring / DUML keys) is the technical ancestor. **Opportunity.** Separate Passports for DroneID-as-broadcast and DUML-as-bus. Do not inherit “fixed” from a paper sentence without a version map. **LRRK relevance.** Campaign the 16 bugs as hypotheses with dispositions. Lab DUML as an untrusted bus. **Confidence.** High on findings. Moderate on CVE absence and patch-version completeness. ## 03. BlueMark DroneScout: first commercial RID-receiver CVEs *Event / publication dates: vendor fix firmware 20230605-1350 (5 June 2023); NVD and Nozomi blog 11 July 2023.* | Field | Value | | --- | --- | | Component | software | | Product | BlueMark Innovations DroneScout ds230, firmware 20211210-1627 through 20230329-1042 (default). ASTM F3411-22a / EN 4709-002 / Open Drone ID receiver. | | CVE / advisory | CVE-2023-31191 (adjacent-channel suppression); CVE-2023-29156 (timing injection); CVE-2023-31190 (update via curl `--insecure`) | | Patch | available. Firmware newer than 20230329-1042 / 20230605-1350. | | Exploit status | public writeup (Nozomi). CISA-ADP SSVC on 29156: exploitation “none.” Not KEV. | | Taxonomy | CWE-223 (CNA, 31191) · CWE-295 (CNA, 31190) · CAPEC-148 · CAPEC-186 · ATT&CK ICS T1692 · T0843 · OWASP IoT I2 · I4 · EMB3D TID-211 | **Verified record — [Fact — A1]** NVD records three CVEs on DroneScout ds230. Nozomi (11 July 2023) described spoofed Open Drone ID replacing real tracks and an insecure firmware-update fetch. Vendor shipped 20230605-1350. **Exposure.** A C-UAS integrator that trusts MQTT-out RID tracks can be shown a false aircraft. The update path is a second Control Fabric hole on the detector. **Intelligence assessment.** [Assessment — High confidence] First CVEs on a commercial broadcast RID receiver. [Assessment — High confidence] Detection stacks inherit the unauthenticated RID broadcast. [Inference — Moderate confidence] Other F3411 receivers share the class even without a CVE. **Opportunity.** Passport RID receivers as “unauthenticated broadcast in, track out.” Watch Swiss CYD / armasuisse RID tools as protocol-property demonstrations, not new OEM bugs. **LRRK relevance.** Sense (detector) and Watch. Kestrel other ODID receivers. Lab spoofed-track acceptance. **Confidence.** High. ## 04. U.S. Army halt of DJI UAS and DJI parts, August 2017 *Event / publication dates: G-3/5/7 memo 2 August 2017; public ~4 August 2017. Navy FOIA letter reported 16 December 2019.* | Field | Value | | --- | --- | | Component | dependency | | Product | All DJI UAS and “any system that employs DJI electrical components or software including… flight computers, cameras, radios, batteries, speed controllers, GPS units, handheld control stations” (memo text via sUAS News). | | CVE / advisory | no CVE. Policy action. Cites classified ARL report 25 May 2017 and Navy memo 24 May 2017. | | Patch | none. Operational ban, not a firmware fix. DJI said it was not consulted. DJI announced Local Data Mode 14 August 2017 and shipped it 2 October 2017. | | Exploit status | none public tied to the memo. Navy FOIA (CyberScoop, December 2019): GCS web-connected “images video and flight records could be uploaded to unsecured servers.” | | Taxonomy | ATT&CK ICS T0862 | **Verified record — [Fact — A1/B2]** The Army memo (published via sUAS News, Defense One, CyberScoop, Ars Technica) ordered units to discontinue DJI UAS and DJI electrical components. The technical finding remains classified. Local Data Mode is a documented vendor process change in the same window. **Exposure.** First major-power treatment of COTS UAV peripherals as a class risk: camera, radio, BMS, ESC, GNSS, GCS. **Intelligence assessment.** [Assessment — High confidence] The memo and its scope are established. [Uncertainty] The classified ARL/Navy technical failure is not public and must not be inferred into a CVE. [Inference — Moderate confidence] This action set the decade’s supply-chain/data-egress policy for kinematic COTS. **Opportunity.** Keep policy actions off the CVE Passport. Record them as Watch context that changes access and update trust. **LRRK relevance.** Watch and Campaign (procurement). Not a Lab-reproducible bug. **Confidence.** High on the memo. Low on the unpublished technical finding. ## 05. Luo, DEF CON 24: consumer hijack model on day one of the window *Event / publication dates: 7 August 2016.* | Field | Value | | --- | --- | | Component | firmware | | Product | DJI Phantom 3 Advanced (radio, Wi-Fi, GPS, app/SDK) | | CVE / advisory | no CVE | | Patch | OEM firmware/app changes over following years; civil GPS itself unchanged | | Exploit status | public writeup (talk, slides, video) | | Taxonomy | CWE-345 (class, GPS half) · CAPEC-148 · ATT&CK ICS T0860 · OWASP IoT I2 · I7 | **Verified record — [Fact — A1]** Aaron Luo, “Drones Hijacking — multi-dimensional attack vectors and countermeasures,” DEF CON 24, 7 August 2016, with slides on media.defcon.org. The talk demonstrated a live consumer-UAV hijack surface across GPS, radio, and app/SDK. **Exposure.** Unauthenticated civil GPS plus unauthenticated local links. Sense and Move on the then-standard consumer airframe. **Intelligence assessment.** [Assessment — High confidence] Window-edge citation that later open-stack and OEM papers keep using for the consumer threat model. [Inference — Moderate confidence] Sathaye et al., USENIX Security 2022, is the in-window update of the GPS-takeover half on current DJI/Autel stacks (see DKSR-R-04). **Opportunity.** Treat Luo as the model, Sathaye as the current-stack evidence. Do not assign a CVE that was never issued. **LRRK relevance.** Sense-Move-Act. Lab civil GNSS as unauthenticated. **Confidence.** High. ## Forward indicators 1. Independent version map for the 2024 DroneID encryption / AeroScope dongle change vs the 2017–2022 NVD fleet. 2. A second commercial RID-receiver CVE family (not BlueMark). 3. CVE assignment for the NDSS 2023 sixteen, or a vendor advisory with versions. 4. Public technical release of the 2017 ARL/Navy DJI finding (unlikely; remains Uncertainty). 5. ASTM F3411 / OpenDroneID cryptographic authenticity, if it ever ships. > **Collection integrity.** NVD, NDSS, Nozomi, DEF CON, contemporary press quoting named researchers, Army memo via named outlets. No KEV. Wartime AeroScope-use reporting is B2/C3 and is not treated as catalogued exploitation. ASTM RID spoofing is a standard property, not an OEM CVE, and is carried as context under signals 01 and 03. CISA/FBI “Chinese-Manufactured UAS” CSA (18 January 2024) and FCC Covered List listing of DJI (December 2025) are policy runners-up, not signals. OnDefend assessment (28 May 2026) is a vendor-commissioned review, not a CVE. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>