Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
History

Thu, 01 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Information Disclosure via Exposed Endpoints Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
References

Thu, 01 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
Title Unauthenticated Information Disclosure via Exposed Endpoints
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-01T18:40:25.139Z

Reserved: 2025-12-16T14:05:31.364Z

Link: CVE-2025-68273

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-01T19:15:53.630

Modified: 2026-01-01T19:15:53.630

Link: CVE-2025-68273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.