← Späť na vyhľadávanie CVE

CVE-2026-58478

Sustainable Irrigation Platform (SIP)

Popis

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase -opendoor- to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible.

CVSS 6.5EPSS 0.261%Riziko 0.67
Zobraziť zdroj
Zverejnené
2026-07-14 15:17:06
Dotknuté verzie
<=5.2.16
Typ
Firmvér
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L