Critical Flaws Found in NASA Spacecraft Control Software Could Allow Unauthorized Commands
Security researchers at Cycode have uncovered a chain of vulnerabilities in AIT-GUI, the browser-based control interface used with NASA/JPL's open-source AMMOS Instrument Toolkit. The flaws, tracked as GHSA-p9r8-2q67-fp86 and rated a near-maximum 9.4 out of 10 on the CVSS severity scale, could allow an attacker with no valid login credentials to send commands directly to a spacecraft or instrument's command system.
While this specific case involves specialised aerospace software, it highlights a broader lesson for all organisations: web-based control panels and management consoles are high-value targets for attackers, and authentication gaps in these systems can have serious consequences. Software that manages critical operations—whether it's spacecraft, industrial equipment, or business infrastructure—needs to be held to a high security standard, including strong authentication checks before any command or action is processed.
Although Australian small businesses are unlikely to run spacecraft control software, many rely on browser-based dashboards to manage cloud services, security cameras, point-of-sale systems, or remote equipment. This case is a reminder to check that such tools require proper authentication and to keep them updated, since a single unauthenticated access flaw can undermine an entire system's security.