CVE-2025-66398
CRITICAL 9.6EPSS 20.1%
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.6 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v3.1
- 9.6 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS
- 20.12% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2026-01-01
- Updated
- 2026-01-05
Proof-of-concept exploits (3)
- advisories/GHSA-w3x5-7c4c-66p9
- showy-headteacher114/cve-2025-663981★ · 2026-08-30
- joshuavanderpoll/cve-2025-66398