Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CWE-74)
A command injection vulnerability exists in Cobham SATCOM VSAT7090 Maritime Satellite Router up to version 20260704 in the JSON Parsing component, specifically in the c_set_reports_decode function of mail-report.sh. The sender/recipients arguments are not properly sanitized, allowing manipulation to inject arbitrary commands.
Any authenticated user with low-level privileges can trigger this vulnerability remotely over the network and execute arbitrary operating system commands with the privileges of the affected process.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Yes, a patch is available.
Update Cobham SATCOM VSAT7090 Maritime Satellite Router to a version beyond 20260704. Restrict network access to the affected device to trusted users only and limit administrative access to the minimum required. Monitor for exploitation attempts targeting the mail-report.sh function. Consider implementing network segmentation to isolate satellite router management interfaces.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-83772 . See article
NVD published the first details for CVE-2026-83772
A CVSS base score of 9.9 has been assigned.
GitHub Advisories released a security advisory .
Links to Mitre Att&cks
Brinztech Alert: Critical Command-Injection Flaw Disclosed in Cobham SATCOM VSAT7090 Routers
CVE Daily Brief — 2026-09-01
[MARITIME SATELLITE SECURITY] — A CRITICAL COMMAND-INJECTION FLAW HAS JUST BEEN DISCLOSED IN COBHAM SATCOM VSAT7090 MARITIME SATELLITE ROUTERS — AND A PUBLIC EXPLOIT ALREADY EXISTSCVE-2026-83772 can allow a low-privileged remote attacker to inject …
FKIE_CVE-2026-83772 - Vulnerability-Lookup
CVE-2026-83772 - Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection CVE ID : CVE-2026-83772 Published : Sept. 1, 2026, 6:16 a.m. | 56 minutes ago Description : A vulnerability was detected in Cobham SATCOM ...
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
