CVE-2026-83772: Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function csetreportsdecode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, requires low privileges, and does not require user interaction. Exploitation involves manipulating the sender or recipients argument processed by c_set_reports_decode in mail-report.sh.
Which systems should be considered exposed?
Cobham SATCOM VSAT7090 Maritime Satellite Router installations up to version 20260704 are identified as affected. The supplied information does not state whether the vulnerable JSON parsing and mail-report functionality is enabled in the default configuration.
How urgent is remediation?
This is rated critical with network attack vector, low attack complexity, and high impact to confidentiality, integrity, and availability. A public exploit is available, so affected systems should be prioritized for remediation and exposure reduction.
What can be done if an update is not immediately available?
The available data does not provide a vendor workaround. Reduce remote reachability to affected routers and restrict access to accounts or interfaces that can supply sender or recipient values until a remediation can be applied.