CVE-2021-34125
HIGHPX4-Autopilot < 1.11.3 - Exposure of Sensitive Information via NuttX Commands
Title source: llmDescription
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands.
References (8)
Core 8
Core References
Exploit, Third Party Advisory
https://gist.github.com/swkim101/f473b9a60e6d4635268402a2cd2025ac
Exploit, Issue Tracking
https://github.com/PX4/PX4-Autopilot/issues/17062
Patch
https://github.com/PX4/PX4-Autopilot/pull/17264/commits/555f900cf52c0057e4c429ff3699c91911a21cab
Patch
https://github.com/apache/incubator-nuttx/pull/3292/commits/016873788280ca815ba886195535bbe601de6e48
Product
https://nuttx.apache.org/
Scores
CVSS v3
7.5
EPSS
0.0096
EPSS Percentile
57.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
dronecode/px4_drone_autopilot
< 1.11.3
yuneec/mantis_q_firmware
Published
Mar 09, 2023
Tracked Since
Feb 18, 2026