Impact
The reported issue in the Robotics-STAR-Lab RACER software allows a malicious actor to trigger a denial of service by exploiting a flaw in its exploration state machine. An improperly handled state transition can cause the application to enter an invalid or infinite processing loop, resulting in a crash or unresponsive behavior. The weakness is a logic error in the state machine implementation, which directly compromises the availability of the system.
Affected Systems
The vulnerability affects the RACER project maintained by the SYSU STAR Group. The impacted version is identified by the commit abcdef1234567890. No other vendor or product versions are listed as affected.
Risk and Exploitability
The CVSS score is not provided, and EPSS data is unavailable, suggesting no publicly available exploit data yet. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves sending specially crafted control inputs to the RACER state machine, which if accepted by the system, will trigger the DoS condition. Because the flaw resides in application logic, a local or remote attacker who can influence the state input can exploit it without requiring privileged access.
OpenCVE Enrichment