CVE 5.3 MEDIUM

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints_CVE-2025-68273

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.

Basic Information

ID CVE-2025-68273
Source GitHub_M
Published Jan 1, 2026 at 18:21
Modified Jan 1, 2026 at 18:40

Affected Product

Vendor SignalK
Product signalk-server
Version < 2.19.0
Affected Versions SignalK signalk-server < 2.19.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.