LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 March 2013 | | Platform | Quiet Systems | | Series | DKSR-M-2013-03 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF The AR.Drone community ships a WPA2 overlay because the stock aircraft still uses an open AP and an unauthenticated telnet root shell on the flight computer. This is a workaround, not a Parrot vendor advisory. ### Key judgments 1. **[Assessment — High confidence]** GitHub repository daraosn/ardrone-wpa2 created 10 March 2013. Documents the open network and an unauthenticated telnet root shell on the flight computer. 2. **[Assessment — Moderate confidence]** Primary source is GitHub metadata, not NVD/IEEE. 3. **[Inference — Moderate confidence]** First dated public patch artifact found for the 2010–2012 AR.Drone open-Wi-Fi class. Later AR.Drone 2.0 papers cite this repo. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. ardrone-wpa2 community hardening of Parrot open Wi-Fi / telnet *Event / publication dates: daraosn/ardrone-wpa2 created 10 March 2013.* | Field | Value | | --- | --- | | Component | software / firmware | | Product | Parrot AR.Drone (community overlay; uses open telnet to install wpa_supplicant) | | CVE / advisory | no CVE | | Patch | partial — unofficial community hardening (WPA/WPA2 client mode). Not a Parrot vendor advisory. | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — B2]** daraosn/ardrone-wpa2, created 10 March 2013. Documents stock open network; unauthenticated telnet; pairing described as MAC-filterable. https://github.com/daraosn/ardrone-wpa2 **Exposure.** Open AP plus unauthenticated root shell on the flight computer. Move and Act. Update path is community-installed. **Intelligence assessment.** [Assessment — Moderate confidence] Creation date is GitHub metadata. [Inference — Moderate confidence] Same failure class already in Deligne 2011 and Samland 2012; this is the patch artifact. **Opportunity.** Watch SkyJack (December 2013). Passport vendor WPA vs community overlay. Do not treat a README as a Parrot close. **LRRK relevance.** Control Fabric. Watch. Lab open-telnet on consumer UAS. **Confidence.** Moderate (GitHub, not NVD/IEEE). ## Forward indicators 1. SkyJack automation of the same open-Wi-Fi class (December 2013). 2. A Parrot vendor security advisory (none identified in 2013 coverage). > **Collection integrity.** One community repo. Not a vendor advisory. Same AR.Drone class as 2010-09 / 2011-12 / 2012-01. Not padded. Public sources only. No invented CVEs. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>