Impact
Ground‑station versions prior to 0.8.0 contain a critical authentication bypass that allows an unauthenticated attacker to execute arbitrary SQL statements while the application is in its initial setup mode. By invoking the setup.restore command through Socket.IO, an attacker can create new administrator accounts and place forged session tokens. Once these tokens are in place the attacker can log in as an administrator without credentials, effectively taking full control of the application. The vulnerability is a missing authentication check for a sensitive function (CWE‑306). The CVE description indicates that the vulnerability is exploitable during first‑run setup mode and that Socket.IO is used to invoke the command. It does not specify whether the Socket.IO endpoint is publicly exposed, so we infer that remote exploitation is possible if the interface is reachable from the network.
Affected Systems
The affected product is sgoudelis:ground‑station, any release before 0.8.0. No narrower version list is supplied, so all pre‑0.8.0 builds are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.3 denotes critical severity. The EPSS score is not available, but the lack of a KEV listing indicates it has not yet been widely exploited in the wild. The description does not state whether the Socket.IO interface is publicly exposed; it is inferred that an attacker could trigger the vulnerability remotely if the interface is reachable from the network. Because the attacker can gain unrestricted administrator rights, the impact on confidentiality, integrity, and availability is complete application takeover.
OpenCVE Enrichment