CVE-2025-68273

MEDIUM

Signal K Server < 2.19.0 - Unauthenticated Exposure of Sensitive System Information

Title source: llm
STIX 2.1

Description

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 5.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
npm/signalk-server 0 - 2.19.0npm
signalk/signal_k_server < 2.19.0
Published Jan 01, 2026
Tracked Since Feb 18, 2026