A critical flaw (CVSS 9.4) in NASA/JPL's AIT-GUI let anyone send unauthenticated commands to spacecraft instruments.