CVE-2026-105105: Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

Published Oct 3, 2026
·
Updated

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the commands command topic. With the shipped default configuration, command messages are forwarded through commandstream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

Affected Software

1 affected component
NASA-AMMOS AIT-Core<=3.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NASA-AMMOS AIT-Core to a version that resolves this vulnerability.

    Fixed in 3.1.2
  2. Compensating control

    For deployments where the ZeroMQ message bus operates across multiple hosts, protect the bus with authenticated and encrypted transport such as ZeroMQ CURVE or an equivalent mutually authenticated TLS-protected network layer.

Event History

Oct 3, 2026
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed by the default configuration?

AIT-Core through 3.1.1 is exposed when an attacker can reach the ait-server ZeroMQ ports over the network. The broker binds to all interfaces by default: TCP 5559 accepts published messages and TCP 5560 permits subscription to command and telemetry traffic.

2

What access does an attacker need to inject commands or observe telemetry?

No authentication, credentials, or user interaction are required. Network reachability to TCP 5559 allows publication to internal topics including __commands__; reachability to TCP 5560 allows subscription to command and telemetry traffic.

3

Could injected messages reach the command uplink path?

Yes. Under the shipped default configuration, messages published to the command topic are forwarded through command_stream and emitted on the command-uplink UDP path.

4

What is the available remediation?

AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback. Systems running through 3.1.1 should be assessed for network exposure of TCP ports 5559 and 5560.

5

How can I determine whether command or telemetry traffic may already have been exposed?

Check whether TCP 5559 or TCP 5560 was reachable by untrusted network clients. Reachability to 5559 permits message publication and disruption, while reachability to 5560 permits subscription to command and telemetry traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203