Executive brief
Navtor NavBox, a maritime navigation data distribution system, contains a vulnerability that allows unauthorized access to internal files. An attacker can remotely access sensitive system configuration and operational data without needing a password. This could lead to the exposure of critical information used for vessel navigation and system management.
Technical details
An absolute path traversal vulnerability (CWE-36) exists in the HTTP service of Navtor NavBox. The application fails to properly sanitize user-supplied path input, allowing unauthenticated remote attackers to bypass directory restrictions by submitting requests containing absolute filesystem paths. Successful exploitation enables the retrieval of arbitrary files from the host operating system, limited by the privileges of the service process. This can result in the exposure of sensitive OS configuration files and system information. The issue is addressed in version 4.14.1.2.
Affected products
- Navtor NavBox 4.12.0.3 up to (but excluding) 4.14.1.2
Timeline
- 2024-12: patched: Version 4.14.1.2 released
- 2026-03-06: disclosed: Initial NVD publication