CVE-2025-68273 Details
Description
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
A vulnerability allowing unauthenticated information disclosure has been identified in Signal K Server versions prior to 2.19.0. This issue arises because several sensitive API endpoints are not properly protected by authentication middleware, allowing any user to access confidential system information. The exposed data includes the complete Signal K data schema, details about connected serial devices, and information on installed analyzer tools. Such exposure could facilitate reconnaissance for further attacks.
Users are advised to update to Signal K Server version 2.19.0 or later. After updating, ensure that the missing paths are added to the authentication middleware's protection list in 'src/tokensecurity.js'.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SignalK/signalk-server/releases/tag/v2.19.0 | [email protected] | Release Notes |
| https://github.com/SignalK/signalk-server/security/advisories/GHSA-fpf5-w967-rr2m | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| signalk signal k server | < 2.19.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 6, 2026 | Initial Analysis | [email protected] |
| Jan 1, 2026 | New CVE Received | [email protected] |