Sceawere

Vulnerability Detail

CVE-2026-19918UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Starlink Router Improper Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
SpaceX
Product
Starlink Router Gen 3
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-16T00:16:50.180Z",
  "pubdate": "2026-08-16T00:16:50.180Z",
  "executiveSummary": "A vulnerability has been identified in the SpaceX Starlink Router Gen 3 firmware version 2025.11.14.mr64708.3, specifically residing within the gRPC Management Interface.\nThe flaw manifests as improper access controls within the get_status function, leading to unauthorized information disclosure and potential security boundary bypass.\nThe affected system is the SpaceX Starlink Router Gen 3 running the specified firmware version.\nRisk implications include unauthorized access to sensitive operational and status data exposed via the management plane, potentially aiding further network reconnaissance or local exploitation.\nAttacker capabilities are constrained by network locality, as the attack vector requires local network access to initiate successfully.\nExploitation requirements dictate that the threat actor must already have access to the local network segment hosting the target router to interact with the gRPC Management Interface.",
  "technicalDetails": "The vulnerability resides in the gRPC Management Interface component of the SpaceX Starlink Router Gen 3, specifically within the execution flow of the get_status function.\nThe root cause stems from improper access controls and insufficient authorization validation prior to servicing requests submitted to the targeted function.\nThe affected software version is 2025.11.14.mr64708.3.\nRegarding network exposure, the gRPC Management Interface listens for incoming requests within the local network boundary, necessitating that the attacker has established a foothold on the internal local area network or connected wireless subnet.\nAuthentication and privilege requirements are bypassed due to the missing access control checks within the vulnerable function, allowing unauthenticated or low-privileged local entities to invoke sensitive operations.\nThe attack flow proceeds as follows: First, the malicious actor establishes connectivity to the local network where the target SpaceX Starlink Router Gen 3 is deployed. Second, the actor formulates a crafted gRPC request targeted at the gRPC Management Interface. Third, the request invokes the vulnerable get_status function without proper verification of caller credentials or authorization levels. Fourth, the component processes the request and improperly returns sensitive status data or executes unauthorized logic, thereby violating the intended security boundaries of the management plane.\nThe post-exploitation impact includes the unauthorized extraction of system telemetry and status metrics, which could be leveraged by an adversary to map the internal routing configuration or identify subsequent attack surfaces within the local network architecture."
}
CVE-2026-19918: Starlink Router Improper Access Control (MEDIUM Severity, CVSS: 6.3) - Sceawere