CVE-2026-83772
moderateCommand Injection in Cobham SATCOM VSAT7090 Maritime Satellite Router
CVE-2026-83772 is a command injection vulnerability (CWE-74/CWE-77) in the c_set_reports_decode function of the mail-report.sh script, part of the JSON-parsing component of the Cobham SATCOM VSAT7090 Maritime Satellite Router, affecting builds up to and including 20260704. A remote attacker with low-privileged access (the CVSS 4.0 vector shows network reachability with low attack complexity but privileged credentials required) can manipulate the sender/recipients argument, causing injected commands to be executed on the router. Successful exploitation yields high impact on confidentiality, integrity, and availability of the device and subsequent systems, effectively amounting to privileged command execution on the satellite terminal. Any operator running VSAT7090 firmware up to 20260704 is affected, and the vendor was contacted before disclosure but did not respond. The exploit is described as public and usable, though no standalone public PoC is catalogued, the flaw is not in CISA KEV, and EPSS currently estimates a 1.7% chance of exploitation within 30 days (76th percentile).
What to do: No fixed release is documented because the vendor did not respond to the disclosure, so inventory networks for VSAT7090 units running builds up to 20260704 and restrict access to the mail-report functionality and management interfaces to trusted hosts and accounts, since exploitation requires privileged credentials. Apply firewall/ACL rules limiting the router's reachability from satellite and onboard networks and review logs for anomalous commands tied to the sender/recipients fields. Monitor the vendor for an updated build beyond 20260704 and verify it when released.
| Cobham SATCOM VSAT7090 Maritime Satellite Router | all builds up to and including 20260704 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.