216.73.217.22

CVE-2025-68930

· Published 23/02/2026 21:19 · Modified 24/02/2026 14:13

Labels: CVE-2025-68930 2026-02-23CVE-2025-68930CWE-1385[email protected]

Essential information

Published
23/02/2026 21:19
Modified
24/02/2026 14:13
Author
Creator
CVSS
7.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

CVSS metrics

Description

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypass the Same Origin Policy (SOP) and establish a full-duplex WebSocket connection using a legitimate user's credentials (JSESSIONID). As of time of publication, it is unclear whether a fix is available.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
traccar / traccar cpe:2.3:a:traccar:traccar:6.11.1:*:*:*:*:*:*:*
traccar / traccar cpe:2.3:a:traccar:traccar:*:*:*:*:*:*:*:*

References