← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2020-12.md
Imported-content SHA-256
a8dba838e116fa06b5b66d1ce7c688ac0b81c057f465fa5ed274327227006291
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 December 2020 |
| Platform | Quiet Systems |
| Series | DKSR-M-2020-12 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

The Mavic 2 RC upgrade-path injection becomes public via gist on 21 December. The June thesis reported it to DJI and did not publish the bug. NVD is February 2021.

### Key judgments

1. **[Assessment — High confidence]** First public technical record is the 21 December 2020 gist. CVE-2020-29664.
2. **[Assessment — High confidence]** Patch is RC firmware 01.00.0510+.
3. **[Assessment — High confidence]** The June 2020 KTH thesis is not a public technical disclosure of this injection.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. CVE-2020-29664: Mavic 2 RC firmware-upgrade injection

*Event / publication dates: 21 December 2020 (gist). NVD 18 February 2021 not used for dating.*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | DJI Mavic 2 Remote Controller firmware before 01.00.0510 (gist: 01.00.0100–01.00.0400) |
| CVE / advisory | CVE-2020-29664 |
| Patch | available — 01.00.0510+ |
| Exploit status | catalogued |
| Taxonomy | CWE-78 (class) · ATT&CK ICS T0843 · OWASP IoT I4 · EMB3D TID-211 |

**Verified record — [Fact — A1] https://gist.github.com/viktoredstrom/2f0463ebe7cd786904f229e11386e817 · https://nvd.nist.gov/vuln/detail/CVE-2020-29664**

**Exposure.** OS command injection in `dji_sys` on a firmware-upgrade packet. The controller, not the airframe.

**Intelligence assessment.** [Assessment — High confidence] RC/goggles need their own Passport.

**Opportunity.** Inventory RC firmware independently of aircraft FW.

**LRRK relevance.** Control Fabric.

**Confidence.** High.

## Forward indicators

1. NVD 18 February 2021 — index only.

> **Collection integrity.** Dating is gist-first. CWE-78 is class (command injection). No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>