Critical Command Injection Vulnerability in Cobham SATCOM Routers

Critical Command Injection Vulnerability in Cobham SATCOM Routers

First seen 1 Sep 2026, 19:00 UTC Feedlywww.brinztech.comvulnerability.circl.lu 74.0

Article Content

Browse articles
ThreatCluster

A critical command-injection vulnerability, tracked as CVE-2026-83772, has been disclosed in Cobham SATCOM VSAT7090 satellite communication routers, affecting maritime fleets globally. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the router's operating system due to improper input handling in the JSON Parsing component. The vulnerability poses severe risks, including traffic interception, total communication blackouts, and potential access to onboard networks. Weaponized exploit code is already circulating, increasing the urgency for mitigation. Maritime operators are advised to isolate management interfaces and apply vendor firmware updates immediately. A patch is available for affected systems, specifically versions up to 20260704. The CVSS score assigned to this vulnerability is 9.9, indicating its critical nature. The situation is evolving, and organizations must act swiftly to protect their infrastructure.

Key Points: • CVE-2026-83772 allows remote command execution on Cobham SATCOM VSAT7090 routers. • Exploit code is publicly available, increasing the risk of attacks on maritime operations. • Immediate isolation of management interfaces and firmware updates are recommended.

Timeline

2026-08-11
CVE-2026-62911 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83772 published
A command-injection vulnerability in Cobham SATCOM VSAT7090 routers was disclosed, affecting maritime communication.
Brinztech
2026-09-01
Public exploit code circulating
Weaponized exploit code for CVE-2026-83772 has been found in public channels, increasing threat levels.
Brinztech
2026-09-01
Patch available for affected routers
Cobham SATCOM has released a patch for the VSAT7090 routers to address the critical vulnerability.
Feedly