CVE-2026-58476Dan-in-ca · Sustainable_irrigation_platform
Vulnerability data via NVD (ingested)
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58476product:"Dan-in-ca Sustainable Irrigation Platform"http.html:"Sustainable Irrigation Platform"More intel sources (5)
vuln:CVE-2026-58476vulnerabilities.cve_id: CVE-2026-58476CVE-2026-58476CVE-2026-58476"CVE-2026-58476" exploit -site:nvd.nist.gov