Impact
A missing default branch in the finite state machine of the RACER autonomy platform causes the system to continue publishing swarm trajectories when a drone enters IDLE. This logic error allows an attacker to influence planned flight paths, potentially resulting in unsafe trajectory planning and UAV collisions. The flaw represents a critical loss of integrity and safety in autonomous flight operations.
Affected Systems
The vulnerability is present in the Robotics‑STAR‑Lab RACER codebase at commit abcdef1234567890. No vendor product enumeration is listed; users operating this specific commit are affected, while newer releases may contain a fix.
Risk and Exploitability
The CVSS score of 9.8 highlights a severe impact, while the EPSS score of less than 1% indicates that public exploitation evidence is currently lacking. The issue is not listed in CISA’s KEV catalog. The likely attack vector is a remote or local interaction that leads the UAV into an IDLE state while trajectory data is still being transmitted; however, the exact method is not detailed in the advisory. Consequently, while exploitation probability is low, the potential for catastrophic operational impact warrants immediate mitigation.
OpenCVE Enrichment