Impact
The vulnerability resides in the c_set_reports_decode function of mail-report.sh, a JSON Parsing component on the Cobham SATCOM VSAT7090 Maritime Satellite Router. Manipulating the sender/recipients argument allows an attacker to inject arbitrary shell commands, giving the adversary unrestricted command execution on the device. The flaw is exploitable remotely and the exploit is publicly available.
Affected Systems
Cobham SATCOM VSAT7090 Maritime Satellite Routers running firmware versions up to and including 20260704 are affected. No further sub‑version detail is provided; any router with a firmware date equal to or older than 20260704 may be vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score of 2% signifies a low yet non‑negligible likelihood of exploitation, and the public availability of a working exploit combined with the vendor’s lack of response increases the real‑world risk. The vulnerability is not listed in the CISA KEV catalogue. The attack can be launched over the network from any host that can interact with the router’s JSON processing service, making the threat surface wide for exposed devices.
OpenCVE Enrichment