---
id: CVE-2025-67780
title: >-
  SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on
  Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC
  requests, aka MARMALADE 2
summary: >-
  SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on
  Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC
  requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting
  a Referer heade…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'
cwe:
  - CWE-306
published: '2025-12-11'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67780'
references:
  - url: 'https://www.akawlabs.com/blog/starlink-grpc-execution'
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
epss: 0.00167
epssPercentile: 0.06403
ingestedAt: '2026-07-10T01:55:22.907Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/SteveAkawLabs/MARMALADE-2-CVE-2025-67780-Exploit'
  checkedAt: '2026-09-24T07:52:54.121Z'
exploitAvailable: true
---

## Overview

SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer header. In some cases, an attacker's ability to read tilt, rotation, and elevation data via gRPC can make it easier to infer the geographical location of the dish. NOTE: this is disputed by the Supplier because unauthenticated LAN gRPC is intended behavior for certain mobile app integration, and because the cross-origin policy is correctly enforced for gRPC-Web (port 9201), i.e., it is not a valid vulnerability report.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
