Executive brief
The Sustainable Irrigation Platform (SIP), a system used for managing automated irrigation, contains a security flaw when the optional Node-RED plugin is installed. An unauthenticated attacker can force the device to send unauthorized web requests to other internal or external systems. This could allow an attacker to bypass network security controls to probe internal networks or interact with other private services that are not normally accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The flaw is located within the optional Node-RED plugin, where the application fails to properly validate destination URLs provided in a callback parameter. By exploiting this lack of validation along with a default passphrase ('opendoor'), a remote, unauthenticated attacker can send blind HTTP requests to arbitrary internal or external hosts. This can be used to scan internal networks, bypass firewalls, or interact with internal services that the SIP device has access to. The vulnerability is tracked as CWE-918.
Affected products
- Dan-in-CA Sustainable Irrigation Platform (SIP) through 5.2.16
Timeline
- 2026-07-14: disclosed: Initial disclosure by Zero Science Lab and VulnCheck
- 2026-07-14: advisory: NVD publication date