Remote Code Execution Vulnerability in Ground Station by SGoudelis
CVE-2026-53451

9.8CRITICAL

Key Information:

Vendor

Sgoudelis

Vendor
CVE Published:
19 August 2026

What is CVE-2026-53451?

Ground Station, a suite for satellite tracking and SDR reception, contains a vulnerability discovered in versions before 0.4.13. An unauthenticated command allows attackers to insert file paths that can lead to unauthorized writing of files outside of designated directories. Specifically, a malicious user could leverage the 'save-waterfall-snapshot' operation to manipulate input and create a logging configuration file. By executing this file during a service restart, the attacker could gain elevated privileges, execute arbitrary code, or induce a persistent crash of the service. This vulnerability poses significant risks to the integrity and availability of the Ground Station platform, underscoring the need for timely updates to version 0.4.13 or later.

Affected Version(s)

ground-station < 0.4.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.