5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
Basic Information
ID
CVE-2025-68273
Source
GitHub_M
Published
Jan 1, 2026 at 18:21
Modified
Jan 1, 2026 at 18:40
Affected Product
Vendor
SignalK
Product
signalk-server
Version
< 2.19.0
Affected Versions
SignalK signalk-server < 2.19.0