NASA's ground control software has a critical vulnerability that could allow third-party access to spacecraft, with further coverage provided by Tech Radar.A browser-based variant of NASA's AMMOS Instrument Toolkit (AIT), specifically versions up to 2.5.1, has a critical vulnerability that could allow an unauthenticated attacker to issue commands to spacecraft and instruments, and potentially execute server-side scripts, as discovered by Cycode researchers. The flaw, disclosed on August 18, 2026, stems from the AIT-GUI running as a web server with an open network interface and lacking authentication, authorization, or cross-site request forgery (CSRF) protection. This allows attackers to exploit basic access-control failings, potentially enabling them to upload files, including malware, directly to NASA craft via a vulnerable browser session.The attacker does not need to be on the same network, as access can be gained through an exposed port or by tricking an operator into visiting a malicious webpage. Cycode advises administrators to upgrade AIT-GUI to version 2.5.2, check console ports, and review command history.Source: Tech Radar
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
