Impact
CubeSpace CW0057 Reaction Wheel firmware prior to version 5.0.20 validates firmware updates with a CRC‑32 check, which verifies image integrity but does not verify its source. This flaw (CWE‑347, Improper Verification of Cryptographic Signature) allows an attacker with direct physical access to upload arbitrary firmware, potentially altering the device’s behavior in an unauthenticated manner. The vulnerability does not support remote exploitation and can only be exercised by someone who can physically interact with the unit.
Affected Systems
The flaw affects CubeSpace CW0057 Reaction Wheels running firmware versions earlier than 5.0.20. Firmware 5.0.20 and later provide optional cryptographic secure boot; activation of the fully immutable signed‑boot mode is required to enforce signature verification and eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 3.3 and an EPSS score of <1% indicate low overall risk, and the vulnerability is not listed in the CISA KEV catalog. Physical access is a prerequisite for exploitation, and a bootloader that can reload known‑good CubeSpace‑supplied firmware exists, so an affected unit cannot be rendered permanently inoperable. Nonetheless, updating the firmware or enabling signed‑boot further mitigates the risk.
OpenCVE Enrichment