Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-83772: Cobham VSAT7090 Router allows remote command injection
CVE-2026-83772 · published 2 days ago
Summary
The VSAT7090 maritime satellite router can be tricked into running unauthorized commands when it processes certain email reports. An attacker can send specially crafted data to gain control of the device, which could disrupt communications or expose data. Install the latest firmware from the vendor or disable the affected mail-report function until a fix is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cobham | satcom vsat7090 maritime satellite router | 20260704 |
Original advisory text
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSO...
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
- https://vuldb.com/vuln/397501 vdb-entry technical-description
- https://vuldb.com/vuln/397501/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-83772 third-party-advisory
- https://vuldb.com/submit/880057 third-party-advisory
- https://uvxbywu62qm.feishu.cn/wiki/ERgywyUVfiUM2lkfVLwc1swknXg?from=from_copylin... exploit
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta