Executive brief
The Sustainable Irrigation Platform (SIP), a system used to manage automated irrigation, contains a critical security flaw in its optional command-line control plugin. An attacker can remotely send malicious commands to the system without needing a password, or by using the default password 'opendoor'. If exploited, this allows an unauthorized person to take full control of the irrigation controller, potentially disrupting water management operations or using the device as a foothold to attack other systems on the network.
Technical details
A command injection vulnerability exists in the optional 'cli_control' plugin of the Sustainable Irrigation Platform (SIP) through version 5.2.16. The flaw is located in the plugin's HTTP endpoint, which fails to properly neutralize special elements used in OS commands. An unauthenticated attacker, or one leveraging Cross-Site Request Forgery (CSRF), can store a malicious payload via this endpoint. The payload is executed when the associated irrigation station is activated. The attack is facilitated by the lack of mandatory passphrase protection or the use of the default passphrase 'opendoor', leading to full remote code execution (RCE) on the underlying host.
Affected products
- Dan-in-CA Sustainable Irrigation Platform (SIP) through 5.2.16
Timeline
- 2026-07-14: advisory: Initial disclosure by VulnCheck and Zero Science Lab