PT-2023-9152 · Spacex · Spacex Starlink Wi-Fi Router Gen 2
Hackintoanetwork
+1
·
Published
2023-10-10
·
Updated
2025-03-27
·
CVE-2023-49965
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
SpaceX Starlink Wi-Fi router Gen 2 versions prior to 2023.48.0
Description
The issue is related to the lack of protection of the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack via the
ssid and password parameters on the Setup Page.Recommendations
For SpaceX Starlink Wi-Fi router Gen 2 versions prior to 2023.48.0, update to version 2023.48.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Setup Page until a patch is available.
Avoid using the parameters
ssid and password in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spacex Starlink Wi-Fi Router Gen 2