Executive brief
Ground Station is a browser-based satellite tracking and control suite. An unauthenticated attacker can remotely delete the entire database and inject fabricated satellite and configuration data by connecting to the Socket.IO server without credentials and sending malicious database commands. This could cause loss of all operational data (orbital sources, hardware configurations, observation schedules) or redirect the ground station to attacker-controlled servers.
Technical details
The vulnerability is an unauthenticated database destruction and arbitrary SQL injection flaw in the Socket.IO server's database_backup event handler. The Socket.IO server listens on port 7000 with authentication disabled and a wildcard CORS policy, allowing any network peer to connect without credentials. An attacker can emit the database_backup event with a malicious full_restore command containing attacker-supplied SQL, which is executed via raw exec_driver_sql without sanitization. This allows dropping all tables and recreating the SQLite database from arbitrary CREATE TABLE and INSERT INTO statements, permanently destroying all satellite records and observation schedules or planting malicious data. The vulnerability requires only network access to port 7000 and no prior authentication.
Affected products
- sgoudelis Ground Station prior to 0.6.0
Timeline
- 2026-08-06: disclosed
- other: Patch expected in version 0.6.0