Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Signalk

First CVE: Jan 1, 2026Active for: 1 yearTotal CVEs: 14
52.6
VTI Score
TOP TARGET

Signalk is a modestly represented but prominent maritime data-integration platform centered on its Signal K Server, which aggregates and distributes vessel sensor and navigation data across marine networks. Its vulnerability profile skews toward serious outcomes, with an elevated share of disclosures reaching critical severity, while the recurring weakness classes—including authentication bypass, sensitive information exposure, OS command injection, and resource-exhaustion flaws—reflect the open-network and command-execution risks inherent to a broadly accessible server component in safety-critical maritime environments. Defenders operating marine systems should treat this vendor's advisories as high-priority given the operational impact potential; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
14.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Signalk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2026
6 months ago
Most Recent CVE
May 9, 2026
76 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-66398HIGH
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`
Jan 1, 20268.839NONO
CVE-2026-33950CRITICAL
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection
Apr 2, 20269.432NONO
CVE-2026-23515HIGH
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to
Feb 2, 20268.831NONO
CVE-2025-68620CRITICAL
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication
Jan 1, 20269.131NONO
CVE-2026-41893HIGH
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are pr
May 9, 20267.530NONO
CVE-2025-69203HIGH
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by
Jan 1, 20268.827NONO
CVE-2026-39320HIGH
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (Re
Apr 21, 20267.526NONO
CVE-2025-68272HIGH
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker
Jan 1, 20267.526NONO
CVE-2025-68619HIGH
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages throug
Jan 1, 20267.225NONO
CVE-2026-35038MEDIUM
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. T
Apr 2, 20266.524NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
57%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low3 (21.4%)
High1 (7.1%)
None10 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Signalk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Signalk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Signalk's Products

View all 1 CNAs →

Top CWEs