Improper Access Controls in SpaceX Starlink Router Gen 3
CVE-2026-19918
Key Information:
- Vendor
Spacex
- Status
- Vendor
- CVE Published:
- 15 August 2026
Badges
What is CVE-2026-19918?
A vulnerability identified in the SpaceX Starlink Router Gen 3 version 2025.11.14.mr64708.3 affects the 'get_status' function of the gRPC Management Interface. This flaw allows for improper access control manipulations and poses a risk to users within the local network. Since its disclosure, the exploit has been made public, increasing the urgency for users to patch or secure their devices. Notably, the vendor was contacted regarding this issue but did not provide a response, raising concerns about ongoing vulnerability management.
Affected Version(s)
Starlink Router Gen 3 2025.11.14.mr64708.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
