Description
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw occurs in the FastExplorationFSM::optTimerCallback function within the exploration manager module of the RACER system developed by the SYSU STAR Group. An unhandled condition in this callback can cause the application to crash or become unresponsive, resulting in a denial of service to the swarm exploration component. This vulnerability is an instance of CWE‑400: Uncontrolled Resource Consumption. According to the CVE description, an attacker can trigger this behavior to disrupt the availability of the robotic swarm mission until a manual restart or patch is applied.

Affected Systems

The Robotics-STAR-Lab RACER software at commit abcdef1234567890 is affected. No other vendor or product versions are known to be affected at this time.

Risk and Exploitability

Severity metrics are complete: the CVSS score is 7.5. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. The vulnerability can cause the swarm exploration component to crash or hang, disrupting mission‑critical robotic operations. The attack vector is inferred to be remote via the control interface that triggers the timer callback.

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the Robotics-STAR-Lab project page for any newer commits or patches that address the optTimerCallback issue and apply them immediately.
  • If a patch is not available, add defensive checks in FastExplorationFSM::optTimerCallback to handle unexpected conditions and prevent crashes.
  • Configure a local watchdog or supervisor to regularly monitor the exploration service and automatically restart it if it becomes unresponsive, thereby reducing the impact of a denial‑of‑service event.

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Timer Callback in RACER Exploration Manager

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Robotics-star-lab
Robotics-star-lab racer
Vendors & Products Robotics-star-lab
Robotics-star-lab racer

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp
References

Subscriptions

Robotics-star-lab Racer
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:57:22.735Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71646

cve-icon Vulnrichment

Updated: 2026-09-14T18:56:59.459Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:45.663

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-71646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption