← العودة للجدول
CVE-2025-66398
CVE-2025-66398 — Signal K Server is a server application that runs on a central hub in a boat. Pr
📅 2026-01-01
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.6 🎯 EPSS 0.14%

📋 الوصف الكامل

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., `security

💻 الأنظمة المتأثرة

Signal K Server

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-66398

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.19.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←