PatchSiren

Zenith Satellite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Zenith Satellite CVE published 2026-09-16

CVE-2025-56563

A Server-Side Request Forgery vulnerability exists in Zenith Satellite Tracker 1.0, specifically in the sat_proxy.php script. This script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. Consequently, an unauthenticated remote attacker can leverage this vulnerability to make arbitrary HTTP and HTTPS requests from the server t [truncated]