External risk intelligence

Zenith Satellite Tracker SSRF Vulnerability Allows Server-Side Request Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-56563

The vulnerability exists in a proxy script designed to fetch remote resources. Such proxy functionality is commonly deployed as a web-facing service or API endpoint to facilitate external communication, making it frequently reachable from the public internet.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical Server-Side Request Forgery vulnerability has been identified in the Zenith Satellite Tracker software. This flaw allows unauthenticated attackers to trick the affected server into making requests to internal systems or cloud services, potentially exposing sensitive data or enabling further malicious activity. The main concern is confirming relevance and exposure.

  • Attackers can force server requests to unauthorized destinations.
  • This could expose internal systems and sensitive data.
  • Confirm if your systems use this software.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can send a specially crafted URL to the `sat_proxy.php` script. This script fails to validate the URL, allowing the attacker to redirect the server to make requests to arbitrary internal or cloud resources. This can lead to the exposure of sensitive data or further compromise of the system.

  • No authentication required.
  • Triggered by a crafted URL parameter.
  • Leads to sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to trick the Zenith Satellite Tracker server into making arbitrary HTTP or HTTPS requests. When supported by the advisory, this could allow an attacker to access internal network resources or cloud metadata services.

  • Server-side requests could be forged.
  • Attacker controls URL without validation.
  • Sensitive information disclosure or further attacks.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery vulnerability in sat_proxy.php impacts Zenith Satellite Tracker. Application owners responsible for this script should first confirm its presence, then assess its reachability and business criticality. Coordination with infrastructure or platform teams may be necessary for remediation, depending on how the tracker is deployed.

  • Application owners should investigate.
  • Verify reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zenith Satellite Tracker?

Zenith Satellite Tracker is a software application used for managing and monitoring satellite communications data. Version 1.0 includes server-side scripts like sat_proxy.php designed to fetch remote resources, which often acts as a bridge for external data integration in ground station or telemetry environments.

What is the Server-Side Request Forgery vulnerability in CVE-2025-56563?

This is a CWE-918 weakness. It occurs when a web application accepts user-provided input—in this case, a URL—and uses it to make a request without validating the destination. This allows an attacker to manipulate the server into acting as a proxy to reach locations it should not access.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specifically crafted request to the sat_proxy.php script containing a malicious URL parameter. The bug is not triggered by standard, legitimate usage of the tracker, but specifically by inputs that bypass the expected network boundaries by pointing the server to unauthorized internal or cloud endpoints.

Do I need to worry about this if my system is internal?

Halo Surface Signal indicates that proxy functionality is often exposed to the internet to facilitate communication. While internal systems may be harder to reach, any instance of sat_proxy.php reachable from an untrusted network or the public internet significantly elevates the risk of an attacker pivoting into your private infrastructure.

What should I do first to address this issue?

Start by identifying all servers running Zenith Satellite Tracker 1.0 and confirm the presence of the sat_proxy.php file. Once located, evaluate whether this script is truly required for your operations and prioritize restricting access to the file while you coordinate with your team on a formal update or removal plan.

References