PT-2026-58031 · Unknown · Sustainable Irrigation Platform
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description
Cross-site request forgery occurs when a logged-in administrator is lured to a malicious page that issues HTTP GET requests. The system fails to perform CSRF token validation or origin verification, allowing remote attackers to execute state-changing administrative actions. These actions include disabling the passphrase, rebooting the device, deleting programs, or installing plugins. In default configurations, these endpoints are exposed to unauthenticated users because no passphrase is required and the default credential is
opendoor.Recommendations
Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later.
Change the default credential
opendoor and enable a strong passphrase to prevent unauthenticated access to administrative endpoints.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sustainable Irrigation Platform