Impact
The vulnerability is an SSRF flaw that permits an attacker to submit a malicious callback URL to the optional Node‑RED plugin endpoint. Because the device does not validate the target and uses the weak default passphrase ‘opendoor’, it will blindly issue HTTP requests to any hostname reachable from the appliance, enabling communication to internal or external hosts that are normally not directly accessible.
Affected Systems
Dan‑in‑CA Sustainable Irrigation Platform version 5.2.16 with the optional Node‑RED plugin installed is affected. No other versions are identified as vulnerable.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw simply by sending a request to the vulnerable callback endpoint without any authentication, making the risk a concern for systems that expose that interface remotely. The lack of destination validation and the default passphrase enable blind outbound HTTP requests to arbitrary internal or external hosts.
OpenCVE Enrichment