Impact
The vulnerability in ZJU‑FAST‑Lab EGO‑Planner‑v2 allows an attacker to induce a denial of service by manipulating the interaction between the trajectory server, the position command to odom conversion module, and the emergency recovery logic. The flaw occurs when the threnteraction flow is triggered, causing the system to enter a recovery loop that halts normal operation. As a result, components responsible for autonomous navigation and decision‑making become unresponsive, violating the availability of the system.
Affected Systems
All versions of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. No other vendors are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity and the EPSS score of <1% suggests very low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require the ability to trigger the threnteraction flow, either locally or through a compromised interface, but no public exploits have been reported. Until a patch or mitigation is applied, the risk of a denial of service remains moderate.
OpenCVE Enrichment