Description
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Insecure UAV Trajectory Planning
Action: Apply Patch
AI Analysis

Impact

A missing default branch in the finite state machine of the RACER autonomy platform causes the system to continue publishing swarm trajectories when a drone enters IDLE. This logic error allows an attacker to influence planned flight paths, potentially resulting in unsafe trajectory planning and UAV collisions. The flaw represents a critical loss of integrity and safety in autonomous flight operations.

Affected Systems

The vulnerability is present in the Robotics‑STAR‑Lab RACER codebase at commit abcdef1234567890. No vendor product enumeration is listed; users operating this specific commit are affected, while newer releases may contain a fix.

Risk and Exploitability

The CVSS score of 9.8 highlights a severe impact, while the EPSS score of less than 1% indicates that public exploitation evidence is currently lacking. The issue is not listed in CISA’s KEV catalog. The likely attack vector is a remote or local interaction that leads the UAV into an IDLE state while trajectory data is still being transmitted; however, the exact method is not detailed in the advisory. Consequently, while exploitation probability is low, the potential for catastrophic operational impact warrants immediate mitigation.

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RACER code to a version that includes the missing default case in the FSM, ensuring trajectory publication stops when the drone enters IDLE.
  • In the absence of an immediate fix, change the UAV firmware or configuration to suppress trajectory data during IDLE or enable a manual override that halts swarm updates.
  • Continuously monitor flight logs and telemetry for events where trajectories are published while a UAV reports IDLE, and alert operators to any anomalies.

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Missing Default Case in RACER FSM Allows Unsafe UAV Trajectory Planning

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Robotics-star-lab
Robotics-star-lab racer
Vendors & Products Robotics-star-lab
Robotics-star-lab racer

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-398
CWE-665

Fri, 11 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Missing Default Case in RACER FSM Allows Unsafe UAV Trajectory Planning
Weaknesses CWE-398
CWE-665

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
References

Subscriptions

Robotics-star-lab Racer
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T15:04:47.013Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71644

cve-icon Vulnrichment

Updated: 2026-09-11T15:04:42.868Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T14:17:32.667

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-71644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')