CVE-2026-85431: MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection

Published Sep 3, 2026
·
Updated

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers.

Affected Software

1 affected component
MOOS essential-moos<=10.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MOOS pMOOSBridge to a version that resolves this vulnerability.

    Fixed in 10.0.1
  2. Configuration

    Disable UDPListen in pMOOSBridge to prevent unauthenticated UDP packet injection when the service is exposed to crafted UDP packets.

    pMOOSBridge UDPListen = disabled

Event History

Sep 3, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

MOOS essential-moos deployments through version 10.0.1 are exposed when pMOOSBridge is configured with UDPListen. The affected UDP port accepts crafted packets that can inject variables into the local MOOS community.

2

Does an attacker need credentials or user interaction to exploit it?

No. The issue is unauthenticated and can be exploited by sending crafted UDP packets to the configured port; no privileges or user interaction are required.

3

What can an attacker falsify through the injected packets?

An attacker can inject arbitrary variables into the local MOOS community and spoof both source and community identifiers.

4

What can be done if an update cannot be applied immediately?

The provided information identifies UDPListen as the affected configuration. Restricting exposure to the configured UDP port or disabling UDPListen where it is not required can reduce exposure, but no vendor-prescribed workaround is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203