PT-2026-68620 · Unknown · Ground Station
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ground Station versions prior to 0.6.0
Description
An unauthenticated denial-of-service issue exists in the Socket.IO server's
service control event handler. Due to disabled authentication enforcement and a wildcard CORS (Cross-Origin Resource Sharing) policy, any network peer can connect to the server on port 7000 without credentials. By emitting the service control event with a restart service command, an attacker can forcibly terminate the ground-station process. This action stops all active satellite-tracking sessions, SDR recording pipelines, demodulators, decoders, and rotator controllers. In Docker deployments, this can be triggered repeatedly to maintain a persistent denial-of-service state.Recommendations
Update Ground Station to version 0.6.0 or later.
Exploit
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ground Station