{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vsat7090-maritime-satellite-router--20260704/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cobham:vsat7090_maritime_satellite_router:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-83772"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VSAT7090 Maritime Satellite Router (\u003c= 20260704)"],"_cs_severities":["critical"],"_cs_tags":["network-security","remote-code-execution","cve-2026-83772"],"_cs_type":"advisory","_cs_vendors":["Cobham"],"content_html":"\u003cp\u003eThe Cobham SATCOM VSAT7090 Maritime Satellite Router, specifically firmware versions up to 20260704, is susceptible to a critical command injection vulnerability (CVE-2026-83772). The vulnerability resides in the c_set_reports_decode function within the mail-report.sh shell script. This component is responsible for parsing JSON data, but it fails to properly sanitize the sender and recipients arguments.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted JSON payload to the device. Because the application processes these arguments in a way that passes them to the underlying system shell, an attacker can inject arbitrary commands. Since the exploit is now public, this represents a significant risk for maritime organizations relying on these satellite communication terminals for external connectivity. The vendor has not provided a patch as of the disclosure date.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the satellite router. Impact includes potential loss of device control, interception of maritime communications, and potential lateral movement into networks connected via the router. All sectors utilizing the VSAT7090 for maritime operations are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for network and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate affected Cobham VSAT7090 devices from the public internet if remote management is not required.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering to limit access to the web interface or management API of the VSAT7090 to known, trusted management IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor web traffic directed to the router for JSON payloads containing shell metacharacters such as semicolon, pipe, or backtick in the sender or recipient fields.\u003c/li\u003e\n\u003cli\u003eContact Cobham support to inquire about firmware updates, as no official patch has been released for CVE-2026-83772.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T07:03:19Z","date_published":"2026-09-01T07:03:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-83772/","summary":"An unauthenticated remote command injection vulnerability in the mail-report.sh script of Cobham SATCOM VSAT7090 devices allows attackers to execute arbitrary system commands via crafted JSON input.","title":"Command Injection in Cobham SATCOM VSAT7090 Maritime Satellite Router","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-83772/"}],"language":"en","title":"CraftedSignal Threat Feed - VSAT7090 Maritime Satellite Router (\u003c= 20260704)","version":"https://jsonfeed.org/version/1.1"}