MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 23:17
Updated : 2026-09-08 20:07
NVD link : CVE-2026-85424
Mitre link : CVE-2026-85424
CVE.ORG link : CVE-2026-85424
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
