CubeSpace CW0057 Reaction Wheel

MonitorCVSS 6.1ICS-CERT ICSA-26-183-02Jul 2, 2026
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The CubeSpace CW0057 reaction wheel uses only a CRC-32 integrity check to validate firmware updates. This check confirms image integrity but does not verify the source of the firmware image. An attacker with direct physical access could upload arbitrary malicious firmware. Starting with firmware version 5.0.20, CubeSpace offers optional cryptographic secure boot that customers can enable to verify firmware authenticity. A compromised device remains recoverable via its bootloader, which can reload known-good firmware images supplied by CubeSpace.

What this means
What could happen
An attacker with physical access to the reaction wheel could upload malicious firmware that alters its operation, potentially affecting satellite attitude control or other spacecraft operations. The device can be recovered through bootloader functions, limiting permanent damage.
Who's at risk
Satellite and space system operators using CubeSpace CW0057 reaction wheels for attitude control. Any space mission or platform integrating this component is potentially affected.
How it could be exploited
An attacker with direct physical access to the CW0057 device would bypass the CRC-32 integrity check (which only verifies data integrity, not source) and upload custom firmware. The bootloader does not validate firmware signatures, allowing arbitrary code execution on the reaction wheel.
Prerequisites
  • Direct physical access to the CW0057 reaction wheel
  • Means to connect to the firmware upload interface (serial or debug port)
  • Knowledge of the upload procedure
physical access requiredno authentication on firmware updatesaffects control systems (attitude control)low complexity attack once physical access gained
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
CW0057 Reaction Wheel<firmware 5.0.20Fix available
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate CW0057 to firmware version 5.0.20 or later
HARDENINGEnable signed-boot functionality in firmware 5.0.20, particularly fully immutable mode, to cryptographically verify firmware authenticity
Long-term hardening
0/1
HARDENINGImplement physical security controls to restrict access to the reaction wheel and its firmware update interfaces (serial/debug ports)
API: /api/v1/advisories/9a97dfea-78b9-4c04-ba0f-d6f1b04adc9b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.