ZeroHour

CVE-2026-85433

niche

Missing Authorization in MOOS essential-moos pShare Allows Bus Traffic Redirection

CVSS 4.0
9.3 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

MOOS essential-moos pShare through version 10.0.1 fails to properly authorize PSHARE_CMD messages (CWE-862), meaning any publisher connected to the MOOS bus can reconfigure network routes and listeners at runtime without restriction. An attacker sends crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations. Successful exploitation gives the attacker high confidentiality, integrity, and availability impact on the affected bus, since they can intercept, divert, or duplicate inter-process communications. Any deployment running pShare in essential-moos version 10.0.1 or earlier is affected, primarily robotics and autonomy research/operational systems that use this middleware. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%, so no exploitation is currently known.

What to do: Upgrade essential-moos/pShare to a release newer than 10.0.1 as soon as a patched version is published (no fixed version is specified in the advisory data). Until then, restrict network access to MOOS bus ports to trusted hosts, limit which nodes may send PSHARE_CMD messages, and check running pShare instances for unexpected listeners or duplicated/redirected traffic on non-standard addresses.

Affected
MOOS essential-moos (pShare)through 10.0.1 (all versions up to and including 10.0.1)
Estimated exposure
nichelikely hundreds to low thousands of deployments (niche robotics middleware; no public install counts available) — MOOS is specialized middleware used mainly in academic and marine-autonomy robotics deployments rather than mass-market software, so the affected install base is plausibly small, though no authoritative install-count data exists.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.