Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.2epss 2.8%
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Dan-in-CA · SIPpublic PoCs found — 1
cve_referencewww.zeroscience.mk/#/advisories/ZSL-2026-5999unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.