Administrative gRPC actions via unauthenticated diagnostic bridge
Published Dec 11, 2025 · Updated Dec 11, 2025
Missing authentication in SpaceX Starlink Dish firmware 2024.12.04.mr46620 allows remote attackers to invoke administrative gRPC actions. The diagnostic HTTP bridge on port 9201 converts attacker-supplied binary POST bodies into gRPC command identifiers and executes permitted commands without authentication; omitting Referer bypasses its cross-origin check. Access requires LAN reachability; demonstrated consequences are orientation-data reads and forced reboot, while SpaceX disputes the report as intended app integration behavior.
Summary
What happened
Missing authentication in SpaceX Starlink Dish firmware 2024.12.04.mr46620 allows remote attackers to invoke administrative gRPC actions. The diagnostic HTTP bridge on port 9201 converts attacker-supplied binary POST bodies into gRPC command identifiers and executes permitted commands without authentication; omitting Referer bypasses its cross-origin check. Access requires LAN reachability; demonstrated consequences are orientation-data reads and forced reboot, while SpaceX disputes the report as intended app integration behavior.
The record
- CVE
- CVE-2025-67780
- Published
- Dec 11, 2025
- Updated
- Dec 11, 2025
- Vendor
- SpaceX
- Product
- Starlink Dish
- Classifications
- CWE-306, T1210, T1498
- Attack vector
- adjacent
- Privileges
- unauthenticated
Timeline
How it unfolded
- Dec 11, 2025CVE publishedPublication date reported by the CVE source.
- Dec 11, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=2024.12.04.mr46620 <21.08.24
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- MARMALADE 2 forced-reboot proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo