VORANT. Threat Intelligence Sign in Get the full feed

CubeSpace reaction wheel firmware lacks signature verification

medium vulnerability telecommunications

A cryptographic signature flaw in CubeSpace CW0057 Reaction Wheel firmware allows attackers with physical access to upload malicious firmware, mitigated by bootloader recovery and optional secure boot in v5.0.20.

CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 contain an Improper Verification of Cryptographic Signature vulnerability (CVE-2026-13743) that allows attackers with physical access to upload arbitrary malicious firmware without authentication. The device authenticates firmware updates using only CRC-32 integrity checks, which verify image integrity but not the source. Exploitation requires direct physical access and cannot be performed remotely.

The vendor has released firmware version 5.0.20, which introduces cryptographically verified secure boot capability; however, this protection is not enabled by default and users must explicitly activate signed-boot functionality to achieve full security. The bootloader operates independently of application firmware and can reload known-good CubeSpace-supplied images, meaning affected devices remain recoverable and cannot be permanently disabled by this method.

CubeSpace assesses the practical risk as low given the physical-access prerequisite and the availability of recovery mechanisms. The affected product is deployed worldwide in the communications sector. CISA recommends organizations implement defense-in-depth strategies and maintain proper network isolation for control system devices.

Mentioned in this report

Vulnerabilities CVE-2026-13743

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free