PT-2026-1015 · Unknown · Signal K Server
Published
2026-01-01
·
Updated
2026-01-12
·
CVE-2025-66398
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Signal K Server versions prior to 2.19.0
Description
Signal K Server, a server application used on boats, is susceptible to an issue where an unauthenticated attacker can manipulate the server's internal state. This manipulation occurs through the
/skServer/validateBackup API endpoint, specifically targeting the restoreFilePath variable. Successful exploitation allows an attacker to hijack the administrator's "Restore" functionality, enabling them to overwrite critical server configuration files such as security.json and package.json. This can lead to account takeover and Remote Code Execution (RCE).Recommendations
Versions prior to 2.19.0 should be updated to version 2.19.0 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Signal K Server