Embodied & Unmanned Red-Team Briefing
具身 / 无人系统安全红队速报
Embodied & Unmanned Red-Team Briefing · 2026-09-06 · No.042 · Lite Edition
具身 / 无人系统安全红队速报 · 2026-09-06 · 第 042 期 · 精简版
10:00 · Sun · Brief10:00 · 周日 · 精简版
Casualty / Loss of Control致伤 / 失控
1
Weekly cum. 3 · ▲1本周累计 3 · ▲1
Single-Unit Takeover单体接管
2
Weekly cum. 7 · ▲2本周累计 7 · ▲2
Function Loss / Data功能失效 / 窃取
1
Weekly cum. 5 · —本周累计 5 · —
Intel / Theory情报 / 理论
2
Weekly cum. 9 · ▲1本周累计 9 · ▲1
NOW
- PX4 CVE-2026-1579 (CVSS 9.8) — MAVLink command channel lacks signature verification; consumer/industrial drones on default configs can be hijacked mid-flight. Gear: SDR or MAVLink-capable radio. Loss of control class.PX4 CVE-2026-1579(CVSS 9.8)— MAVLink 指令通道缺少签名校验,默认配置下的消费级 / 工业级无人机可在飞行中被接管。装备:SDR 或 MAVLink 电台。属"载具失控"级。
- Everon OCPP backend (CISA ICSA-26-062-08, CVSS 9.4) — WebSocket accepts station-ID with no auth; predictable session IDs enable hijack. Legit charging network 3.2M€ fraud already demonstrated in the wild.Everon OCPP 后端(CISA ICSA-26-062-08,CVSS 9.4)— WebSocket 用桩 ID 直连无鉴权,会话 ID 可预测导致劫持。欧洲某充电网络已现 320 万欧元实盗损失。
WEEK
- SROS2 design flaws (V1-V3) — permission revocation, namespace isolation, discovery topology leak. Requires custom test bench; targets ROS 2 fleets that "believe they are secured".SROS2 三处设计缺陷(V1-V3)— 权限撤销不彻底、命名空间隔离不足、发现协议泄漏拓扑。需自建测试台架;针对"以为已启用安全"的 ROS 2 机队。
- BadRobot line — jailbreak of embodied LLM (Voxposer / Code as Policies / ProgPrompt) turns voice instructions into hazardous physical actions. New RoboJailBench (2606.19328) extends coverage to drones and humanoids.BadRobot 线路 — 越狱 Voxposer / Code as Policies / ProgPrompt 类具身 LLM,将语音指令翻译成危险物理动作;新出 RoboJailBench(2606.19328)把评测扩到无人机与人形。
RANGE
- PX4 in Gazebo + QGroundControl swarm sim: verify MAVLink signature retrofit and swarm-scale spoofing resilience. Do not test on real airframes in public airspace.Gazebo + QGroundControl 蜂群仿真下验证 MAVLink 签名回填与集群欺骗韧性;禁止在公共空域真机验证。
- OCPP backend in isolated docker + charger emulator: replay `RemoteStartTransaction` and hijack station identifiers. Do not aim at live public stations.隔离 docker + 充电桩模拟器复现 `RemoteStartTransaction` 与桩 ID 劫持;禁止指向真实公共桩。
§2 Communication Link Hijack通信链路劫持
Loss of Control致伤 / 失控
PX4 MAVLink command channel unauthenticated — CVE-2026-1579 (CVSS 9.8) still exploitable on default buildsPX4 MAVLink 指令通道未鉴权 —— CVE-2026-1579(CVSS 9.8)默认构建仍可利用
Loss of Control致伤/失控
PoC publicPoC 公开
Media
Business-relevant业务相关
2026-04-07
CVE-2026-1579 · CVSS v3.1 9.8 · Gear: SDR (HackRF/BladeRF ~$300-500) or MAVLink telemetry radio · Range: line-of-sight RF · Cost: $100-1K装备:SDR(HackRF/BladeRF 约 $300-500)或 MAVLink 电台 · 距离:视距 RF · 成本:$100-1K
Attack chain: PX4 accepts unsigned MAVLink control frames on the default GCS channel — an attacker within RF range or on any GCS network segment can inject MAV_CMD_NAV_LAND, DO_FLIGHTTERMINATION or arbitrary waypoint commands. Chains cleanly to loss-of-control or targeted crash. Maps to ATT&CK for ICS T0855 Unauthorized Command Message.
攻击链:PX4 默认 GCS 通道接受未签名 MAVLink 控制帧 —— RF 视距内或 GCS 同网段的攻击者可注入 MAV_CMD_NAV_LAND、DO_FLIGHTTERMINATION 或任意航点指令,直接触发失控或定向坠机。挂 ATT&CK for ICS T0855 未授权指令。
Reproduction essentials复现要点
Gear: SDR + open-source MAVLink stack (pymavlink/QGroundControl). Prerequisite: sniff sysid/compid from any beacon frame. Expected physical effect: waypoint override / forced landing / terminate. Retrofit MAVLink 2 signing before validating on any real airframe; validate only in Gazebo + QGC swarm sim, no live airspace.
装备:SDR + 开源 MAVLink 栈(pymavlink/QGroundControl)。前置:从任一广播帧嗅探 sysid/compid。预期物理效果:航点覆盖 / 强制降落 / 终止。真机验证前须先回填 MAVLink 2 签名,且仅在 Gazebo + QGC 蜂群仿真中验证,禁止在真实空域。
§3 Robot Stack & Buses机器人栈与总线
Single-Unit Takeover单体接管
SROS2 three-way design flaw — permission-revocation gap + namespace-isolation gap + discovery-topology leakSROS2 三处设计缺陷 —— 权限撤销失效 + 命名空间隔离不足 + 发现协议拓扑泄漏
Single-Unit Takeover单体接管
Requires custom gear需自制设备
Verified
Sector signal赛道信号
2026-08 review
Ref: NTU On the (In)Security of Secure ROS2 · Gear: DDS-XRCE / Fast-DDS test client · Range: LAN-adjacent · Cost: $0 (all open-source)参考:NTU On the (In)Security of Secure ROS2 · 装备:DDS-XRCE / Fast-DDS 测试客户端 · 距离:局域网相邻 · 成本:$0(开源即可)
Attack chain: even with SROS2 "enabled", revoked participants keep publishing until their token expires; namespaces overlap enough for a compromised node to read siblings; the discovery handshake leaks topology to any passive listener. Combines into enum → replay → cross-namespace command injection on ROS 2 humanoids and quadrupeds.
攻击链:即便开启 SROS2,被撤权的参与者仍可发布消息直至令牌过期;命名空间隔离不完全,被攻陷节点可读同类兄弟;发现握手对被动监听方直接泄漏拓扑。可组合为 枚举 → 重放 → 跨命名空间指令注入,命中 ROS 2 人形与四足机队。
Reproduction essentials复现要点
Gear: two-node Fast-DDS or Cyclone DDS testbench + SROS2 sample keystore. Prerequisite: attach to the same L2 segment (wired or Wi-Fi bridge). Expected effect: send commands to /cmd_vel or manipulator topics after being "revoked". Do not run against production robots; use a bench robot with e-stop.
装备:双节点 Fast-DDS 或 Cyclone DDS 台架 + SROS2 样例证书库。前置:接入同一 L2 段(有线或 Wi-Fi 桥)。预期效果:撤权后仍能向 /cmd_vel 或机械臂话题发指令。禁止对生产机器人运行;台架机需有物理急停。
§4 Embodied Agents & Autonomous Decision自主决策与具身 Agent
Single-Unit Takeover单体接管
BadRobot → RoboJailBench: jailbreak-to-physical-action now benchmarked across manipulators, drones, humanoidsBadRobot → RoboJailBench:越狱转物理动作已扩展评测机械臂 / 无人机 / 人形
Single-Unit Takeover单体接管
PoC publicPoC 公开
Trusted
Sector signal赛道信号
2026-08
Ref: arXiv 2407.20242 (BadRobot, ICLR'25) + 2606.19328 (RoboJailBench) · Gear: text/voice input, benchmark harness · Range: any user-facing agent interface · Cost: <$100参考:arXiv 2407.20242(BadRobot,ICLR'25)+ 2606.19328(RoboJailBench)· 装备:文本 / 语音输入 + 评测框架 · 距离:任何用户可达的 Agent 接口 · 成本:<$100
Attack chain: three failure modes — (1) LLM manipulation inside the robotic stack; (2) linguistic-to-physical action misalignment; (3) world-knowledge blindspots yielding unintended harms. Validated on Voxposer / Code as Policies / ProgPrompt. Maps to ATLAS AML.T0051 LLM Prompt Injection → self-defined physical-execution stage.
攻击链:三种失效 — ①栈内 LLM 被操控;②语言输出与物理动作不对齐;③世界知识盲点导致意外伤害。已在 Voxposer / Code as Policies / ProgPrompt 验证。挂 ATLAS AML.T0051 提示词注入 → 自建"物理执行"阶段。
Reproduction essentials复现要点
Gear: any embodied-LLM demo (open-source Voxposer/CoP) + a safe manipulator or sim (Isaac / PyBullet). Prerequisite: user-facing voice or text channel. Expected effect: agent executes hazardous rearrangement / hand-off / self-destruct macro. Sim first; if using real arm, cage it and cut power to end-effector during trigger.
装备:任一开源具身 LLM Demo(Voxposer/CoP)+ 安全机械臂或仿真(Isaac / PyBullet)。前置:可达的语音 / 文本通道。预期效果:Agent 执行危险重排 / 交接 / 自毁宏。先仿真;如上真机须笼装、触发时切断末端执行器供电。
§6 Cloud / Fleet Backend云-端与队列管理
Loss of Control致伤 / 失控
Everon OCPP backend — WebSocket accepts station-ID with no auth, session-ID predictable → in-the-wild €3.2M lossEveron OCPP 后端 —— WebSocket 用桩 ID 直连无鉴权、会话 ID 可预测,已现 320 万欧元实盗损失
Loss of Control致伤/失控
PoC publicPoC 公开
Verified
Business-relevant业务相关
2026-03 · 2026-09 recap
CISA ICSA-26-062-08 (Everon) · ICSA-26-057-07 (ev.energy) · CVSS 9.4 · Gear: standard wscat + Python · Range: internet · Cost: $0装备:标准 wscat + Python · 距离:互联网 · 成本:$0
Attack chain: attacker enumerates or discovers a valid charge-point ID (public disclosures, Shodan-style), opens a WebSocket to the OCPP backend using that ID and no credential; the backend accepts, the most-recent socket displaces the legit charger. From there: fake RemoteStart/Stop, inject payment ledger, DoS the fleet. Chains to grid-edge disruption at scale (37% of stations still on OCPP 1.6 per 2026 tracking).
攻击链:攻击者枚举 / 拿到合法桩 ID(公开披露 / Shodan 类),以该 ID 无凭据打开 OCPP WebSocket,后端接受、最近连接顶替合法桩;随后可伪造 RemoteStart/Stop、篡改计费、拒服务队列。规模化即为电网边缘扰动(2026 跟踪:37% 桩仍跑 OCPP 1.6)。
Reproduction essentials复现要点
Gear: docker-based OCPP simulator + wscat. Prerequisite: a known valid charge-point ID (self-issued in the lab). Expected effect: session hijack, fake charge transaction. Only against your own emulator or a vendor-provided sandbox; never a live public station.
装备:docker 化 OCPP 模拟器 + wscat。前置:合法桩 ID(自建实验室下发)。预期效果:会话劫持、伪造计费。仅对自建模拟器或厂商沙箱验证,绝不指向真实公共桩。
§7 Supply Chain & Regulation供应链与法规
Intel / Theory情报 / 理论
CFID vuln DB tops 3,700 connected-car entries · CN embodied-intelligence standard system (2026 ed.) issued中汽 CFID 智能网联汽车漏洞库突破 3,700 · 《人形机器人与具身智能标准体系(2026 版)》发布
Intel / Theory情报/理论
Paper-only仅论文
Verified
Sector signal赛道信号
2026-02 → 2026-09
Ref: CFID (3,700+ entries · 1,000+ models) · MIIT humanoid & embodied std sys 2026 · Gear: — · Range: — · Cost: —参考:CFID(3,700+ 条 · 1,000+ 车型)· 工信部人形与具身标准体系 2026 · 装备:— · 距离:— · 成本:—
Red-team read: the CN connected-car vuln surface is now large enough that vendor-agnostic sweeps yield hits, while the humanoid/embodied standard is defining "trusted" data-quality and evaluation criteria — 2026 is when domestic humanoids first face third-party sec-test gating. Expect procurement pressure to filter through supply chain by year-end.
红队解读:国内智能网联汽车漏洞面已到"跨厂扫描即有命中"的规模;同时具身标准在定义"可信"数据质量与评测口径 —— 2026 是国产人形首次面临第三方安全评测门禁。年底前应可见到供应链端的采购压力传导。
Reproduction essentials复现要点
Not applicable — track item. Action: subscribe to CFID and MIIT/CAICT bulletins; map own product-line exposure against category buckets (Bluetooth / Wi-Fi / TSP / V2X / OTA).
不适用 — 追踪项。行动:订阅 CFID 与工信部 / 信通院公告;按类目桶(蓝牙 / Wi-Fi / TSP / V2X / OTA)比对自身产品线暴露。
Long-tail Tracking · not yet actionable长尾追踪 · 尚未可行动
- Fiber-optic FPV drones displacing RF ones — 35+ CN/UA producers by early 2026, Russian adoption 30-50% on some fronts. Red-team read: RF-jam-based C-UAS is losing ground; next verticals to watch are optical cable severance and terminal seizure. Intel-layer only.光纤 FPV 挤压 RF FPV — 2026 初已有 35+ 中乌厂商量产,俄军部分前线渗透率 30-50%。红队解读:基于射频的反无人机路线正在失效;下一步观察光纤断线与末端夺取。仅情报层。
- Waymo blackout freeze incident (SF) — during an outage, robotaxis halted at dark intersections, stranding vehicles in-lane. Not an attack but exposes a rich fault-injection surface (traffic-signal loss = degraded-mode entry). Sim it in CARLA before framing as red-team scenario.旧金山 Waymo 断电冻结事件 — 停电导致机器出租车停在无信号灯路口、堵在车道内。非攻击事件,但暴露了丰富的故障注入面(信号灯失效即降级入口)。先在 CARLA 里仿真再纳入红队方案。