CVE-2025-68930Disclosure(traccar / traccar)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypass the Same Origin Policy (SOP) and establish a full-duplex WebSocket connection using a legitimate user's credentials (JSESSIONID). As of time of publication, it is unclear whether a fix is available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traccar

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-23); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
traccar

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2302-2402-2702-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-68930 Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket`… https://www.cve.org/CVERecord?id=CVE-2025-68930

    Post summary

    CVE‑2025‑68930 affects Traccar versions up to 6.11.1, exposing a Cross‑Site WebSocket Hijacking vulnerability in the `/api/socket` endpoint.

    00010119
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-68930 Cross-Site WebSocket Hijacking in Traccar GPS Tracking System Versions 6.11.1 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-68930

    Post summary

    A new CVE (CVE-2025-68930) describing a Cross‑Site WebSocket Hijacking vulnerability in Traccar GPS Tracking System versions 6.11.1 and below has been disclosed, with no PoC, exploit, or patch details provided.

    0001051
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-68930 (CVSS:7.1, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack..https://nvd.nist.gov/vuln/detail/CVE-2025-68930 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2025‑68930, a high‑severity Cross‑Site WebSocket Hijack affecting Traccar up to version 6.11.1, noting its CVSS score and linking to the NVD entry.

    0000075
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-68930 (CVSS:7.1, HIGH) is Analyzed. Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack..https://nvd.nist.gov/vuln/detail/CVE-2025-68930 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A CVSS 7.1 high‑severity vulnerability (Cross‑Site WebSocket Hijack) in Traccar 6.11.1 and earlier has been identified; no PoC, exploit, or patch details are provided.

    0000021
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraccartraccar---

Explore more