CVE-2025-68273Medium· 5.3▾ TwilightPoC availableSignal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the ful…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Nuclei ×1 (last check)
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
signal_k_server < 2.19.0Upgrade past the affected range:
signal_k_server 2.19.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66398Critical· 9.6Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68620Critical· 9.1Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-69203Medium· 6.3Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68619High· 7.2Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68272High· 7.5Signal K Server is a server application that runs on a central hub in a boat
CVE-2026-35038Medium· 6.5Signal K Server is a server application that runs on a central hub in a boat