CVE-2025-66398Critical· 9.6▾ AbyssalPoC availableSignal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.8 · likelihood 4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
20%
2 GitHub repos (last check)
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (restoreFilePath) of the server via the /skServer/validateBackup endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., security.json, package.json), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.
signal_k_server < 2.19.0Upgrade past the affected range:
signal_k_server 2.19.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68273Medium· 5.3Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68620Critical· 9.1Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-69203Medium· 6.3Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68619High· 7.2Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68272High· 7.5Signal K Server is a server application that runs on a central hub in a boat
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.