Impact
The vulnerability is in the get_status function of the gRPC Management Interface on SpaceX Starlink Router Gen 3 firmware 2025.11.14.mr64708.3. A malicious actor on the same local network can manipulate this function to bypass the router’s access controls, allowing them to retrieve status information that should be restricted. The attack does not provide code execution but can expose internal configuration details, potentially aiding further attacks or service enumeration.
Affected Systems
SpaceX Starlink Router Gen 3 running firmware 2025.11.14.mr64708.3 is the only identified affected product. No other versions or product lines have been reported vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the attack can only be initiated from the local network, the risk is confined to environments where an attacker can physically or remotely gain local connectivity. The exploit has already been publicly disclosed, so adversaries can use it without additional effort. Given the lack of an official vendor patch, the ongoing risk remains until a fix is released or the service is disabled.
OpenCVE Enrichment