Description
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-15
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the get_status function of the gRPC Management Interface on SpaceX Starlink Router Gen 3 firmware 2025.11.14.mr64708.3. A malicious actor on the same local network can manipulate this function to bypass the router’s access controls, allowing them to retrieve status information that should be restricted. The attack does not provide code execution but can expose internal configuration details, potentially aiding further attacks or service enumeration.

Affected Systems

SpaceX Starlink Router Gen 3 running firmware 2025.11.14.mr64708.3 is the only identified affected product. No other versions or product lines have been reported vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the attack can only be initiated from the local network, the risk is confined to environments where an attacker can physically or remotely gain local connectivity. The exploit has already been publicly disclosed, so adversaries can use it without additional effort. Given the lack of an official vendor patch, the ongoing risk remains until a fix is released or the service is disabled.

Generated by OpenCVE AI on August 16, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure network segmentation or firewall rules to restrict access to the router’s gRPC management port to trusted devices only.
  • Disable the gRPC management interface or enforce strong authentication so that only authorized devices can invoke get_status.
  • Continuously monitor router logs for unexpected or repeated get_status requests and investigate any anomalies.

Generated by OpenCVE AI on August 16, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title SpaceX Starlink Router Gen 3 gRPC Management get_status access control
First Time appeared Spacex
Spacex starlink Router Gen 3
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:h:spacex:starlink_router_gen_3:*:*:*:*:*:*:*:*
Vendors & Products Spacex
Spacex starlink Router Gen 3
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:A/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Spacex Starlink Router Gen 3
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T23:15:09.251Z

Reserved: 2026-08-15T05:11:48.781Z

Link: CVE-2026-19918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T00:16:50.180

Modified: 2026-08-16T00:16:50.180

Link: CVE-2026-19918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T00:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control