news.mlab.sh
Back to the feed
vulnerability

NAVTOR NavBox

Critical
Summary

A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Foundation (SOAP) implementation. This could lead to disruption of operations and potential file manipulation. The vulnerability has been patched, but organizations are advised to implement defensive measures to minimize risk.

This vulnerability, reported by Cydome Security Ltd and tracked by CISA, affects NAVTOR NavBox, a product used within critical infrastructure sectors, specifically Information Technology. The core issue lies in the hard-coded credentials embedded within the SOAP interface of the software. If this interface is enabled, a local attacker can extract these credentials and leverage them to bypass intended workflows, ultimately gaining access to privileged WCF methods. This allows for the writing or overwriting of files within application-defined paths, representing a significant security risk. The vulnerability is considered high severity due to its potential impact and relatively high attack complexity.

Read the full article at CISA Advisories