Junglewise Threat Intelligence

CVE-2026-2752: Navtor NavBox information disclosure in AIS data API

CVE-2026-2752 · Severity: medium · CVSS 5.3 · Published 2026-03-06

Technologies: NAVTOR Navbox Firmware, NAVTOR NavBox. Vendors: NAVTOR.

Executive brief

Navtor NavBox, a maritime gateway used for distributing navigational data and managing ship-to-shore communications, contains a security flaw in its web interface. An unauthorized person can access internal system data and trigger error messages that reveal how the software is built. This could allow an attacker to gain sensitive information about the vessel's internal network and operational technology, potentially aiding in more complex cyberattacks.

Technical details

A missing authentication and improper error handling vulnerability (CWE-209) exists in the Navtor NavBox /api/ais-data endpoint. A remote, unauthenticated attacker can send specially crafted HTTP requests to this endpoint to trigger unhandled exceptions. The server responds with verbose .NET stack traces that reveal sensitive internal details, including class names, method calls, and references to third-party libraries like System.Data.SQLite. Additionally, the lack of authentication allows for the retrieval of unencrypted JSON objects containing environmental data and operational telemetry. This vulnerability was addressed in firmware version 4.16.2.4.

Affected products

  • Navtor NavBox 4.12.0.3 up to (excluding) 4.16.2.4

Timeline

  • 2025-11: patched: Firmware version 4.16.2.4 released.
  • 2026-03-06: disclosed: Initial NVD publication.

References

Related threats