CVE-2026-58479Dan-in-ca · Sustainable_irrigation_platform
Vulnerability data via NVD (ingested)
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58479product:"Dan-in-ca Sustainable Irrigation Platform"http.html:"Sustainable Irrigation Platform"More intel sources (5)
vuln:CVE-2026-58479vulnerabilities.cve_id: CVE-2026-58479CVE-2026-58479CVE-2026-58479"CVE-2026-58479" exploit -site:nvd.nist.gov