← Back to browse · API

CVE-2026-23515

Severity
CRITICAL
CVSS
10.0
EPSS
0.04163
Risk score
41.46
CISA KEV
No
PoC
No
Published
2026-02-02
Modified
2026-02-03
First seen
2026-08-07
Aliases
EUVD-2026-5282, GHSA-P8GP-2W28-MHWG
Products
SignalK:signalk-server < 1.5.0
Sources
euvd EUVD-2026-5282

Description

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.

References