CISA flags CVE-2026-13743 in CubeSpace reaction wheels
The medium score hides the useful detail: secure boot arrives only after operators install 5.0.20 and turn it on.
TL;DR
CISA published CVE-2026-13743 for CubeSpace CW0057 reaction wheels running firmware before 5.0.20, a CVSS v3.1 6.1 Medium flaw allowing a physical-access attacker to upload malicious firmware without authentication. Space-adjacent operators, including defense-industrial-base and state security teams tracking communications assets, should patch and manually enable signed boot, preferably fully immutable mode. CubeSpace calls practical risk low, but optional secure boot keeps the hard part on the operator.
This is a firmware-custody advisory more than a network-exposure advisory. CISA says CW0057 reaction wheels deployed worldwide are affected before firmware 5.0.20 because CRC-32 checks image integrity but does not verify the image source. CubeSpace’s low-risk assessment has a real basis: exploitation requires direct physical access, is not remotely exploitable, and the bootloader can reload known-good CubeSpace images. The operational instruction is still easy to miss. Firmware 5.0.20 only introduces cryptographically verified secure boot, and CISA says users must activate signed-boot functionality, particularly fully immutable mode, to get the full protection. For remote, classified, or supplier-maintained units, that means patching is only half the job; the maintenance process has to prove the setting actually changed.
Published ·Deep Fathom