Description
A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP and HTTPS requests from the server to internal networks or cloud metadata services, potentially obtaining sensitive information or pivoting to further attacks.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch Now
AI Analysis

Impact

An attacker can supply an arbitrary URL to the sat_proxy.php script in Zenith Satellite Tracker 1.0, causing the server to execute a curl request to the supplied address. This server‑side request forgery allows the attacker to reach internal network endpoints or cloud metadata services, potentially exposing confidential data or providing a foothold for subsequent attacks. The vulnerability is a classic input‑validation flaw identified as CWE‑918 and results in unauthorized external network requests from the server's host.

Affected Systems

The vulnerability affects Zenith Satellite Tracker version 1.0. No additional vendor or product information is listed beyond that version; users operating this specific release must verify whether they are running it or a derivative that includes the sat_proxy.php component.

Risk and Exploitability

The CVSS score of 9.8 indicates a high‑severity risk, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker would need to target the exposed sat_proxy.php endpoint and supply a crafted URL; no authentication is required, making the attack path straightforward from the public network. The impact can range from sensitive data disclosure to pivoting toward internal resources, depending on the server’s network environment.

Generated by OpenCVE AI on September 18, 2026 at 11:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest version of Zenith Satellite Tracker once it is released or apply any vendor‑provided patch that removes the unvalidated URL handling.
  • If a patch is not yet available, restrict outbound traffic from the server to limit communication to approved destinations only, preventing internal network or cloud metadata access.
  • Implement validation logic within sat_proxy.php that allows only approved schemes and hosts, or block the endpoint entirely if it is not necessary for normal operation.

Generated by OpenCVE AI on September 18, 2026 at 11:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP and HTTPS requests from the server to internal networks or cloud metadata services, potentially obtaining sensitive information or pivoting to further attacks.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-17T17:03:20.190Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-56563

cve-icon Vulnrichment

Updated: 2026-09-17T17:02:36.349Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:06.537

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-56563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:45:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)