Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.3epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase 'opendoor' to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Dan-in-CA · SIPpublic PoCs found — 1
cve_referencewww.zeroscience.mk/#/advisories/ZSL-2026-5998unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.