Ship satellite routers have a public exploit and no patch

Published

A maritime satellite router used to keep ships online has a command-injection flaw with a public exploit and, so far, no fix. The bug, CVE-2026-83772, affects the Cobham SATCOM VSAT7090 Maritime Satellite Router, and the VulDB entry that assigned it says the vendor was contacted early about the disclosure but did not respond in any way.

Peru's national digital security centre (CNSD) pushed the flaw to operators in its 3 September bulletin, noting that exploit code is already public even though the flaw has not been added to CISA's catalogue of exploited vulnerabilities.

A mail-report script that runs what it is told

According to the CVE record, the weakness sits in the function c_set_reports_decode of the file mail-report.sh, part of the router's JSON parsing component. Manipulating the sender or recipients argument results in command injection, meaning attacker-supplied text reaches the operating system as a command. The record says the attack can be launched remotely and affects VSAT7090 firmware up to version 20260704.

VulDB scores it 8.6 (High) on CVSS 4.0 and 9.9 (Critical) on CVSS 3.1. Both vectors require low privileges, so an attacker needs some level of access to the router first; neither requires any user interaction. The US National Vulnerability Database has published the record but marks it as deferred, so the scores are the numbering authority's, not NVD's own.

Why a satellite router matters more than a printer

At sea, a satellite terminal is frequently a vessel's only link to shore. CNSD's assessment is that a successful attacker could run arbitrary commands on the device's underlying operating system, putting the integrity, confidentiality and availability of the ship's satellite communications at risk. It follows last month's CISA advisories on ship transponders, and it joins a lengthening list of embedded devices shipping serious flaws with no patch on offer.

No patch, so limit who can reach the router

There is no vendor advisory to link and no fixed firmware to install. CNSD advises operators to check with Cobham SATCOM for patch availability. Until one exists, the sensible general precautions for a device with a known injection flaw apply: restrict access to the router's management interface to trusted networks, review who holds credentials on it, and watch for unexpected processes or outbound connections from the terminal. The exploit write-up referenced in the CVE record sits on a collaboration platform that requires a login, so IntelFusions has not reviewed the exploit itself.

A vendor that does not answer a coordinated disclosure leaves its customers to do the vendor's job. For fleets running the VSAT7090, that job starts now.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions