← Back to browse · API

CVE-2025-66398

Severity
CRITICAL
CVSS
9.7
EPSS
0.18231
Risk score
45.18
CISA KEV
No
PoC
Yes
Published
2026-01-01
Modified
2026-01-05
First seen
2026-08-07
Aliases
EUVD-2025-206140, GHSA-W3X5-7C4C-66P9
Products
SignalK:signalk-server < 2.19.0
Sources
github ed69929b5d484c1e0176d601|CVE-2025-66398
euvd EUVD-2025-206140

Description

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.

References