Freetakserver UI Project maintains a narrowly scoped web interface component for the FreeTAKServer tactical data-sharing platform, a purpose-built tool for military and emergency-response coordination. The vendor's vulnerability footprint, while limited in scope, reflects the complexity inherent to a networked command-and-control interface operating in security-sensitive environments. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freetakserver Ui Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25510HIGH FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. | Mar 11, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-25512HIGH FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. | Mar 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25508HIGH An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large a | Mar 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25506MEDIUM FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser. | Mar 11, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-25507MEDIUM FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter. | Mar 11, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-25511MEDIUM An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system. | Mar 11, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freetakserver Ui Project.
Media articles that mention a CVE ID that affects a product developed by Freetakserver Ui Project — matched by CVE ID, not by vendor name.