
🛰️🚨 CRITICAL NASA SPACECRAFT SOFTWARE FLAW ALLOWS UNAUTHENTICATED COMMAND INJECTION A critical vulnerability has been disclosed in: NASA AMMOS AIT-CORE CVE-2026-105105 CVSS: 9.8 AIT-Core is software used for spacecraft command and telemetry operations. The problem is unusually serious. Its core telemetry/command server exposes its ZeroMQ message bus on: 0.0.0.0 with NO authentication or transport security by default. An attacker who can reach TCP port 5559 can publish directly onto internal topics — including: __commands__ With the default configuration, those messages can travel through the command stream and reach the: SPACECRAFT COMMAND-UPLINK PATH. Potential impact: * Inject arbitrary spacecraft command data * Read real-time telemetry * Forge telemetry shown to operators * Manipulate monitoring/limit-check data * Disrupt the command and telemetry bus No credentials. No user interaction. No additional plugin required. The researcher demonstrated the issue live against AIT-Core 3.1.1 and published a working proof-of-concept. Affected: AIT-Core <= 3.1.1 Fixed: AIT-Core 3.1.2 The fix changes the ZeroMQ XSUB/XPUB interfaces from all network interfaces to: 127.0.0.1 There is currently NO evidence that CVE-2026-105105 has been exploited in the wild. ⚠️ Analyst Note: This is not "remote control of NASA spacecraft from the Internet." Network access to the vulnerable AIT server is still required. But the security boundary is remarkable: A system responsible for spacecraft command + telemetry could expose its internal message bus without authentication under its shipped default configuration. And the impact isn't merely server compromise. The vulnerable data path reaches the spacecraft command-uplink pipeline itself. Original NASA-AMMOS advisory + technical details: https://github.com/NASA-AMMOS/AIT-Core/security/advisories/GHSA-ccw5-g774-3683 #NASA #SpaceSecurity #CVE2026105105 #CyberSecurity #Vulnerability #ThreatIntel #DDW


