CVE-2026-21404 is a medium-severity vulnerability in NAVTOR NavBox versions up to 4.16.1.20. The issue arises from hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If SOAP functionality is enabled, a local attacker can extract these credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged [truncated]
CVE-2026-2754 is a HIGH-severity vulnerability in Navtor NavBox, a navigation system used in maritime applications. The vulnerability has a CVSS score of 7.5 and was published on March 6, 2026. The issue arises from missing authentication on HTTP API endpoints, allowing unauthenticated remote attackers with network access to the device to execute HTTP GET requests to TCP port 8080. This can lead to the re [truncated]
CVE-2026-2753 is a HIGH-severity vulnerability in Navtor NavBox, with a CVSS score of 7.5. The vulnerability exists due to improper sanitization of user-supplied path input in the exposed HTTP service. This allows unauthenticated remote attackers to submit requests containing absolute filesystem paths, potentially leading to the exposure of sensitive configuration files and system information.
CVE-2026-2752 is a medium-severity vulnerability in Navtor NavBox that allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library references (e.g., System.Data.SQLit [truncated]