CVE-2026-105105: Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the commands command topic. With the shipped default configuration, command messages are forwarded through commandstream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NASA-AMMOS AIT-Coreto a version that resolves this vulnerability.Fixed in 3.1.2 - Compensating control
For deployments where the ZeroMQ message bus operates across multiple hosts, protect the bus with authenticated and encrypted transport such as ZeroMQ CURVE or an equivalent mutually authenticated TLS-protected network layer.
Event History
Frequently Asked Questions
Which systems are exposed by the default configuration?
AIT-Core through 3.1.1 is exposed when an attacker can reach the ait-server ZeroMQ ports over the network. The broker binds to all interfaces by default: TCP 5559 accepts published messages and TCP 5560 permits subscription to command and telemetry traffic.
What access does an attacker need to inject commands or observe telemetry?
No authentication, credentials, or user interaction are required. Network reachability to TCP 5559 allows publication to internal topics including __commands__; reachability to TCP 5560 allows subscription to command and telemetry traffic.
Could injected messages reach the command uplink path?
Yes. Under the shipped default configuration, messages published to the command topic are forwarded through command_stream and emitted on the command-uplink UDP path.
What is the available remediation?
AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback. Systems running through 3.1.1 should be assessed for network exposure of TCP ports 5559 and 5560.
How can I determine whether command or telemetry traffic may already have been exposed?
Check whether TCP 5559 or TCP 5560 was reachable by untrusted network clients. Reachability to 5559 permits message publication and disruption, while reachability to 5560 permits subscription to command and telemetry traffic.