PT-2026-58047 · Unknown+1 · Sustainable Irrigation Platform+1

·

CVE-2026-58478

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description A server-side request forgery (SSRF) issue exists when the optional Node-RED plugin is installed. Unauthenticated attackers can force the device to issue arbitrary blind HTTP requests to internal or external hosts by providing a malicious callback URL. This is possible due to a lack of destination validation and the use of the default passphrase opendoor.
Recommendations Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later. Change the default passphrase opendoor to a secure one. Disable the Node-RED plugin if it is not required.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92376
CVE-2026-58478

Affected Products

Node-Red
Sustainable Irrigation Platform