External risk intelligence

Signal K Server JWT Token Theft Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-68620

Signal K Server is designed for use as a central hub on boats, typically operating within local maritime networks. While the application utilizes network protocols, it is not inherently designed for public internet exposure, and common deployment patterns involve isolated environments rather than public-facing web infrastructure.

Authentication Bypass

Signalk Signal K Server

before 2.19.02.19.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in Signal K Server could allow unauthenticated attackers to steal authentication tokens, enabling them to bypass security controls and potentially hijack legitimate device credentials. This issue affects systems that manage data for maritime applications. The main concern is confirming relevance and exposure.

  • Steal authentication tokens without needing a password.
  • Potential for unauthorized access to vessel systems.
  • Verify if this server is used and confirm exposure.

Attack Path

How an attacker could exploit the issue

An attacker can steal authentication tokens by chaining two unauthenticated features in Signal K Server. First, they can monitor WebSocket streams to gather details about pending access requests, including request IDs. Then, they can poll the status of these requests, and if an administrator approves one, the attacker intercepts the resulting JWT token.

  • No prior authentication needed.
  • Steal tokens upon request approval.
  • Full authentication bypass.

Live Threat

Current exploitation, exposure, and threat context

Signal K Server versions prior to 2.19.0 could allow an unauthenticated attacker to steal JWT authentication tokens. This is achievable by chaining two features: WebSocket-based request enumeration to gather information about access requests and unauthenticated polling of an access request status endpoint, which reveals the token when an administrator approves the request.

  • Authentication tokens could be stolen.
  • Attacker monitors or initiates access requests.
  • Unauthorized access to legitimate device credentials.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Signal K Server, used as a central hub on boats, is affected by a critical vulnerability. Owners of vessels and maritime operations utilizing this software must prioritize identifying all instances of Signal K Server, assessing their network exposure, and confirming operational criticality to determine the appropriate response. Coordination with potential vendor support for updates is crucial for mitigating this risk.

  • Vessel and operations owners should own the issue.
  • Verify server network reachability and business criticality.
  • Plan and execute updates during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Signal K Server?

Signal K Server is a centralized software hub used on boats to collect, process, and distribute marine data. It acts as an integration layer for various onboard sensors and instruments, helping vessel operators manage navigation and system information within a unified maritime digital ecosystem.

What does CVE-2025-68620 mean for security?

This vulnerability involves an authentication bypass, classified as CWE-288. It allows unauthorized users to retrieve sensitive JSON Web Tokens (JWTs) used for system access. By exploiting flaws in how the server handles event streams and request polling, an attacker can obtain these credentials without ever needing a valid password or prior authorization.

How can an attacker trigger this bug?

The attack requires chaining two unauthenticated actions: monitoring the server's WebSocket stream to discover access request IDs, and polling those IDs to capture issued tokens. Simply connecting to the server does not immediately compromise data; the theft typically occurs when an administrator interacts with the system to approve a pending request.

Is my vessel's server at risk?

Halo Surface Signal indicates that this software is usually deployed in isolated maritime networks, making broad public internet exposure less likely. However, you should check if your server is reachable from outside your local vessel network, as any internet-facing configuration significantly increases the potential for unauthorized access.

How do I secure my Signal K Server?

The primary solution is to update your software to version 2.19.0 or later, which contains the official fix for these authentication issues. As a first step, verify your current version number and plan an update window to apply the patch, ensuring your vessel's communication systems are protected from unauthorized credential theft.

References