CVE-2025-56563

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP and HTTPS requests from the server to internal networks or cloud metadata services, potentially obtaining sensitive information or pivoting to further attacks.
Configurations

No configuration.

History

17 Sep 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-918

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 18:16


NVD link : CVE-2025-56563

Mitre link : CVE-2025-56563

CVE.ORG link : CVE-2025-56563


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)