Impact
The vulnerability resides in the c_set_reports_decode function of mail-report.sh, a JSON Parsing component on the Cobham SATCOM VSAT7090 Maritime Satellite Router. Manipulating the sender/recipients argument allows an attacker to inject arbitrary shell commands, giving the adversary unrestricted command execution on the device. The flaw is exploitable remotely and the exploit is publicly available.
Affected Systems
Cobham SATCOM VSAT7090 Maritime Satellite Routers running firmware versions up to and including 20260704 are affected. No further sub‑version detail is provided; any router with a firmware date equal to or older than 20260704 may be vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. Although the EPSS score is not available, the public availability of a working exploit and the lack of vendor response raise the likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The attack can be launched over the network from any host that can interact with the router’s JSON processing service, making the threat surface wide for exposed devices.
OpenCVE Enrichment