PT-2026-58031 · Unknown · Sustainable Irrigation Platform

·

CVE-2026-58476

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description Cross-site request forgery occurs when a logged-in administrator is lured to a malicious page that issues HTTP GET requests. The system fails to perform CSRF token validation or origin verification, allowing remote attackers to execute state-changing administrative actions. These actions include disabling the passphrase, rebooting the device, deleting programs, or installing plugins. In default configurations, these endpoints are exposed to unauthenticated users because no passphrase is required and the default credential is opendoor.
Recommendations Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later. Change the default credential opendoor and enable a strong passphrase to prevent unauthenticated access to administrative endpoints.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92318
CVE-2026-58476

Affected Products

Sustainable Irrigation Platform