CVE-2026-2754

7.5

Navtor · NavBox

Navtor NavBox exposes sensitive configuration and operational data, including ECDIS and OT information, due to missing authentication on HTTP API endpoints.

Executive summary

An unauthenticated remote attacker can access sensitive operational data on Navtor NavBox devices via an insecure HTTP API, posing a significant risk to maritime OT infrastructure.

Vulnerability

This vulnerability is categorized as CWE-306, where the device fails to perform authentication for critical HTTP API functions. An unauthenticated attacker with network access can execute GET requests on TCP port 8080 to exfiltrate internal system parameters, service logs, and device identifiers.

Business impact

The exposure of sensitive ECDIS and operational technology (OT) data could lead to severe security implications, including unauthorized reconnaissance of critical navigation systems. With a CVSS score of 7.5, this high-severity flaw enables remote actors to gain deep visibility into the shipboard environment, potentially facilitating further, more disruptive attacks against internal networks.

Remediation

Immediate Action: Update the Navtor NavBox firmware to version 4.16.2.4 or later to resolve the missing authentication flaw.

Proactive Monitoring: Review access logs for unauthorized HTTP GET requests targeting TCP port 8080 and monitor for anomalous data egress from affected devices.

Compensating Controls: Restrict network access to the NavBox API endpoints using firewall rules or network segmentation to ensure only authorized management segments can communicate with the device.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the critical nature of the information exposed by this vulnerability, administrators should prioritize patching their Navtor NavBox systems immediately. If an immediate update is not feasible, strict network segmentation is required to prevent unauthorized remote access to the vulnerable API port.

Sources

Originally found and disclosed by Cydome Security Ltd, per the CVE Program record.