CyberRota Analysis
AI-GeneratedThe Sustainable Irrigation Platform (SIP) through version 5.2.16 is vulnerable to a command injection flaw in the cli_control plugin, enabling unauthenticated attackers to execute arbitrary operating system commands. This vulnerability arises from the lack of passphrase protection, allowing exploitation through the plugin's HTTP endpoint when activating an irrigation station. Organizations using this platform should prioritize remediation to prevent potential unauthorized access and control over their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.
Related CVEs
Other vulnerabilities affecting the same vendor(s)