« Volver al listado

Signalk

Signalk Signal K Server: vulnerabilidades y CVE

Signalk Signal K Server tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses15
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-55591Media (5.8)0.30%—15 sept 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters…
CVE-2026-41893Alta (8.7)0.51%—9 may 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default:…
CVE-2026-39320Alta (7.5)0.66%—21 abr 2026
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket…
CVE-2026-35038Baja (2.1)0.41%—2 abr 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a…
CVE-2026-34083Media (6.1)0.14%—2 abr 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where the unvalidated HTTP…
CVE-2026-33951Media (6.9)0.54%—2 abr 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation…
CVE-2026-33950Crítica (9.4)0.48%—2 abr 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated…
CVE-2026-25228Media (4.3)0.43%—2 feb 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to…
CVE-2026-23515Alta (8.8)4.6%—2 feb 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on…
CVE-2025-69203Alta (8.8)0.30%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information…
CVE-2025-68620Crítica (9.1)0.54%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior…
CVE-2025-68619Alta (7.3)0.71%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the…
CVE-2025-68273Media (5.3)0.82%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information,…
CVE-2025-68272Alta (7.5)0.56%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by…
CVE-2025-66398Alta (8.8)20%—1 ene 2026
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1059 Command and Scripting Interpreter3
  3. T1078 Valid Accounts3
  4. T1203 Exploitation for Client Execution2
  5. T1210 Exploitation of Remote Services2
  6. T1499.004 Application or System Exploitation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.