A vulnerability in SpaceX Starlink Wi-Fi router GEN 2 (prior to firmware 2023.53.0) and Starlink Dish (prior to firmware 07dd2798-ff15-4722-a9ee-de28928aed34) allows attackers to perform Cross-Site Request Forgery (CSRF) attacks by leveraging DNS Rebinding. This can be exploited to perform unauthorized actions such as rebooting the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a browser-based DNS rebinding exploit kit built on the NCC Group Singularity framework and customized for Starlink targets. It is not just a detector: it includes a full attack workflow, from target discovery to payload delivery and data exfiltration. Repository structure: the root contains the main web application files and an almost identical duplicate under html/. Core components are manager.js (attack orchestration/UI logic), payload.js (rebind execution and post-rebind request handling), scan-manager.js plus scan.js (parallel HTTP port scanner using web workers and no-cors fetch probes), flushdnscache.js (DNS cache flooding worker), manager-config.json (attacker/target defaults and payload registry), and several HTML front ends: poc.html (interactive PoC UI labeled CVE-2023-52235), autoattack.html (fully automated scan-and-attack page), scan-manager.html (scanner UI), and singularity.html (landing page). Main capabilities: autoattack.html can scan localhost/private targets such as 127.0.0.1 and 0.0.0.0 across selected ports, optionally infer more addresses via local/public IP discovery, and invoke app.attackTarget() on discovered HTTP services. payload.js handles the rebinding lifecycle, supports both fetch-based and iframe-based attack methods, checks whether rebinding succeeded by inspecting response headers/body, and then dispatches a selected payload from the Registry. The framework also supports DNS cache flooding to accelerate rebinding. Starlink-specific purpose: manager-config.json is preconfigured for a Starlink-themed deployment using attack domain starlink.poc.st, attacker IP 111.118.50.147, and default target 192.168.1.1. Included payloads target the Starlink gRPC-web endpoint /SpaceX.API.Device.Device/Handle. The stow and unstow payloads send binary protobuf-like request bodies to control a Dishy terminal. The WifiGetConfig and WifiGetClients payloads query router configuration and connected-client information. These payloads log and alert the response, then POST the raw response bytes to http://sehyou.ng:3000/attacker, indicating explicit exfiltration behavior. Overall, this is a weaponized browser exploit package for DNS rebinding against local network services, with a generic fetch payload and specialized Starlink control/data-theft payloads. The duplicated html/ tree appears to be a mirrored webroot copy of the same exploit assets.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.