CVE-2026-2754
7.5Navtor · NavBox
Navtor NavBox exposes sensitive configuration and operational data, including ECDIS and OT information, due to missing authentication on HTTP API endpoints.
Executive summary
An unauthenticated remote attacker can access sensitive operational data on Navtor NavBox devices via an insecure HTTP API, posing a significant risk to maritime OT infrastructure.
Vulnerability
This vulnerability is categorized as CWE-306, where the device fails to perform authentication for critical HTTP API functions. An unauthenticated attacker with network access can execute GET requests on TCP port 8080 to exfiltrate internal system parameters, service logs, and device identifiers.
Business impact
The exposure of sensitive ECDIS and operational technology (OT) data could lead to severe security implications, including unauthorized reconnaissance of critical navigation systems. With a CVSS score of 7.5, this high-severity flaw enables remote actors to gain deep visibility into the shipboard environment, potentially facilitating further, more disruptive attacks against internal networks.
Remediation
Immediate Action: Update the Navtor NavBox firmware to version 4.16.2.4 or later to resolve the missing authentication flaw.
Proactive Monitoring: Review access logs for unauthorized HTTP GET requests targeting TCP port 8080 and monitor for anomalous data egress from affected devices.
Compensating Controls: Restrict network access to the NavBox API endpoints using firewall rules or network segmentation to ensure only authorized management segments can communicate with the device.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the critical nature of the information exposed by this vulnerability, administrators should prioritize patching their Navtor NavBox systems immediately. If an immediate update is not feasible, strict network segmentation is required to prevent unauthorized remote access to the vulnerable API port.
Sources
Originally found and disclosed by Cydome Security Ltd, per the CVE Program record.