Impact
Signal K Server, a server application running on a central hub aboard a boat, contained a Server‑Side Request Forgery flaw before version 2.28.0. In that version, the makeRemoteRequest() function accepted attacker‑controlled host, port, useTLS, and selfsignedcert values from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the destination. When a security configuration was not present, addAdminMiddleware() performed no authentication, thereby exposing these endpoints freely. An attacker could force the server to reach loopback, private, link‑local, cloud metadata, or arbitrary external endpoints, including disabling certificate verification for outbound HTTPS requests via selfsignedcert. The checkAccessRequest endpoint also interpolated requestId into the destination path, allowing traversal to other paths on the chosen host. Distinct success, connection‑refused, and timeout responses enabled internal port scanning; the returned body content permitted cloud‑metadata and internal‑service data exfiltration; requestAccess enabled arbitrary server‑side POST requests with attacker‑controlled JSON, and access to cluster‑internal services could facilitate lateral movement. This issue is fixed in the 2.28.0 release.
Affected Systems
The vulnerability applies to Signal K Server (SignalK:signalk-server) versions prior to 2.28.0. Any deployment running these older image tags is susceptible.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate impact and the EPSS score of <1% suggests a low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation of the publicly exposed testSignalKConnection, requestAccess, and checkAccessRequest endpoints. Successful exploitation requires no additional privileges, as the security middleware is absent; the attacker can perform internal port scanning, metadata theft, and lateral movement within the ship’s network. The risk is elevated for installations lacking authentication and those exposing the vulnerable endpoints to the internet.
OpenCVE Enrichment
Github GHSA