#Signalk
Avnav ist schon cool, hier mit SignalK Anbindung, der wiederum von meinem ESP32 mit Daten aus dem nmea2000 Netz gefüttert wird.
May 22, 2026 at 6:38 PM
SignalK signalk-server <2.25.0 has a HIGH severity flaw: attackers can brute force passwords via WebSocket with no rate limit. Upgrade to 2.25.0+ to stay protected. 🔒 https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #cybersecurity #vuln
CVE-2026-41893: CWE-307: Improper Restriction of Excessive Authentication Attemp
SignalK signalk-server versions before 2.25.0 implement rate limiting on HTTP login endpoints but do not apply any rate limiting on the WebSocket login mechanism. This allows an attacker to bypass the express-rate-limit protections by sendi
radar.offseq.com
May 10, 2026 at 10:30 AM
CVE-2026-41893 - Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)
CVE ID : CVE-2026-41893

Published : May 9, 2026, 8:16 p.m. | 33 minutes ago

Description : Signal K Server is a server application that runs on a central hub in a boat...
CVE-2026-41893 - Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path — sending {login: {username, …
cvefeed.io
May 9, 2026 at 9:16 PM
Just released: Ecowitt GW2000 plugin for @signalk.org

www.npmjs.com/package/sign...

#signalk #iot #ecowitt
www.npmjs.com
May 5, 2026 at 1:53 PM
🚨 EUVD-2026-24021
📊 7.5/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expres...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24021

#cybersecurity #infosec #cve #euvd
April 21, 2026 at 2:01 AM
📌 CVE-2026-33950 - Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerab... https://www.cyberhub.blog/cves/CVE-2026-33950
CVE-2026-33950
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, a
www.cyberhub.blog
April 7, 2026 at 11:40 AM
CVE-2026-35038 - signalk-server: Arbitrary Prototype Read via `from` Field Bypass
CVE ID : CVE-2026-35038

Published : April 2, 2026, 5:16 p.m. | 38 minutes ago

Description : Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2....
CVE-2026-35038 - signalk-server: Arbitrary Prototype Read via `from` Field Bypass
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from …
cvefeed.io
April 2, 2026 at 6:45 PM
🚨 EUVD-2026-18396
📊 2.1/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18396

#cybersecurity #infosec #cve #euvd
April 2, 2026 at 6:03 PM
🚨 EUVD-2026-18372
📊 9.4/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerabilit...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18372

#cybersecurity #infosec #cve #euvd
April 2, 2026 at 6:02 PM
🚨 EUVD-2026-18376
📊 6.1/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18376

#cybersecurity #infosec #cve #euvd
April 2, 2026 at 6:02 PM
🚨 EUVD-2026-18374
📊 6.9/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticate...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18374

#cybersecurity #infosec #cve #euvd
April 2, 2026 at 6:02 PM
🚨 EUVD-2026-5343
📊 5.0/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicatio...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5343

#cybersecurity #infosec #cve #euvd
February 4, 2026 at 10:43 PM
🚨 EUVD-2025-206140
📊 9.7/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the inter...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206140

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:32 PM
🚨 EUVD-2025-206139
📊 7.5/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206139

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:31 PM
🚨 EUVD-2025-206138
📊 5.3/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206138

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:31 PM
🚨 EUVD-2025-206137
📊 7.3/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206137

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:31 PM
🚨 EUVD-2025-206136
📊 9.1/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206136

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:31 PM
🚨 EUVD-2025-206135
📊 6.3/10
🏢 SignalK

📝 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related fea...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206135

#cybersecurity #infosec #cve #euvd
January 1, 2026 at 10:31 PM
You can now share your thoughts on vulnerability CVE-2025-69203 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-69203

SignalK - signalk-server

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-69203
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
January 1, 2026 at 6:56 PM
You can now share your thoughts on vulnerability CVE-2025-68620 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-68620

SignalK - signalk-server

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-68620
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
January 1, 2026 at 6:56 PM
You can now share your thoughts on vulnerability CVE-2025-68619 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-68619

SignalK - signalk-server

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-68619
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
January 1, 2026 at 6:56 PM
CVE-2025-68272 - Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
CVE ID : CVE-2025-68272

Published : Jan. 1, 2026, 6:08 p.m. | 17 minutes ago

Description : Signal K Server is a server application that runs on a central hub in a bo...
CVE-2025-68272 - Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of …
cvefeed.io
January 1, 2026 at 6:43 PM
You can now share your thoughts on vulnerability CVE-2025-68273 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-68273

SignalK - signalk-server

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-68273
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
January 1, 2026 at 6:46 PM