CVE-2025-67780 - CERT CVE
ID CVE-2025-67780
Sažetak SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer header. In some cases, an attacker's ability to read tilt, rotation, and elevation data via gRPC can make it easier to infer the geographical location of the dish.
Reference
CVSS
Base: 4.2
Impact: 2.5
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE LOW
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Zadnje važnije ažuriranje 12-12-2025 - 00:15
Objavljeno 11-12-2025 - 23:15