PatchSiren cyber security CVE debrief
CVE-2026-75371 SpaceDot CVE debrief
A physically-proximate attacker with UART access can cause a Denial of Service (DoS) via a crafted input due to an integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec. This vulnerability requires verification of UART access controls and validation of input to the cobs_decode function to prevent potential Denial of Service (DoS) attacks. The flaw is located in the cobs_decode function, which handles integer values improperly, allowing attackers to exploit this weakness.
- Vendor
- SpaceDot
- Product
- AcubeSAT OBC software
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-24
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-24
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for SpaceDot AcubeSAT OBC software systems should assess exposure and verify UART access controls. They should also validate input to the cobs_decode function to prevent potential Denial of Service (DoS) attacks. This vulnerability impacts operators, platforms, vulnerability management, and security teams, emphasizing the need for thorough review and mitigation.
Why it matters
Defenders should care about CVE-2026-75371 because it allows a physically-proximate attacker with UART access to cause a Denial of Service (DoS) via a crafted input, requiring verification of UART access controls and validation of input to the cobs_decode function.
- Denial of Service (DoS) via crafted input
- Verification of UART access controls is necessary
- Validation of input to the cobs_decode function is required
Technical summary
The cobs_decode function in SpaceDot AcubeSAT OBC software commit eaf90ec has an integer handling flaw that allows a physically-proximate attacker with UART access to cause a Denial of Service (DoS) via a crafted input. This technical issue requires defenders to focus on verifying UART access controls and validating input to the cobs_decode function to mitigate potential attacks.
Defensive priority
Defenders should prioritize verifying UART access controls and validating input to the cobs_decode function.
Recommended defensive actions
- Verify UART access controls
- Validate input to the cobs_decode function
- Monitor for crafted input attempts
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the integer handling flaw in the cobs_decode function. The source details are limited, so defenders should verify UART access controls and validate input to the cobs_decode function. Evidence limits suggest that further verification is required to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75371 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75371
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75371 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75371
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/dazuo233/cve/issues/6
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.