CVE-2025-68930 | Traccar up to 6.11.1 Websocket Connection /api/socket missing origin validation in websockets (GHSA-69x6-wcx2-vghp)
A vulnerability classified as critical has been found in Traccar up to 6.11.1. This affects an unknown part of the file /api/socket of the component Websocket Connection Handler. This manipulation causes missing origin validation in websockets.
This vulnerability is tracked as CVE-2025-68930. The attack is possible to be carried out remotely. No exploit exists.