Executive brief
NAVTOR NavBox, a maritime navigational data distribution system, contains a security flaw where login credentials are permanently embedded in its communication software. A person with local access to the system could discover these credentials and use them to bypass security controls. This could allow an unauthorized user to modify or delete critical application files, potentially disrupting maritime operations or navigational data integrity.
Technical details
The vulnerability (CWE-798) exists in the Windows Communication Foundation (WCF) SOAP implementation of NAVTOR NavBox. Hard-coded credentials within the SOAP functionality can be extracted by a local attacker with low privileges. Once extracted, these credentials allow the attacker to authenticate against the SOAP interface and access privileged WCF methods. This access enables the attacker to perform file write or overwrite operations within application-defined paths. The attack complexity is considered high because it requires local access and specific conditions for the SOAP functionality to be enabled. A patch was released in April 2026 (version 4.17.2.6) which is automatically deployed to connected devices.
Affected products
- NAVTOR NavBox through 4.16.1.20
Timeline
- 2026-04: patched: NAVTOR released version 4.17.2.6 to address the issue.
- 2026-06-04: disclosed: Initial publication of ICSA-26-155-01.