← العودة للجدول
CVE-2025-68620
CVE-2025-68620 — Signal K Server is a server application that runs on a central hub in a boat. Ve
📅 2026-01-01
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.1 🎯 EPSS 0.06%

📋 الوصف الكامل

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated polling of access request status. The first is Unauthenticated WebSocket Request Enumeration: When a W

💻 الأنظمة المتأثرة

Signal K Server

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-68620

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.19.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←