OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2025-56563

CRITICAL · CVSS 9.8 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery vulnerability in the sat_proxy.php script of Zenith Satellite Tracker 1.0 allows unauthenticated remote attackers to manipulate the URL parameter, enabling them to send arbitrary HTTP and HTTPS requests from the server. This could lead to exposure of sensitive information from internal networks or cloud metadata services, facilitating further attacks. Organizations using this software should prioritize patching this vulnerability to mitigate potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-56563
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%

Original NVD Description

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP and HTTPS requests from the server to internal networks or cloud metadata services, potentially obtaining sensitive information or pivoting to further attacks.