Sgoudelis Ground-Station vulnerabilities
3 known vulnerabilities affecting sgoudelis/ground-station.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-103244P2CRITICALCVSS 9.8fixed in 0.8.02026-10-01
CVE-2026-103244 [CRITICAL] CWE-306 CVE-2026-103244: ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.res
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without cr
nvd
CVE-2026-53451P2CRITICALCVSS 9.8fixed in 0.4.132026-08-19
CVE-2026-53451 [CRITICAL] CWE-22 CVE-2026-53451: Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits
nvd
CVE-2026-53452P4MEDIUMCVSS 5.3fixed in 0.4.132026-08-19
CVE-2026-53452 [MEDIUM] CWE-22 CVE-2026-53452: Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py
nvd