Executive brief
Navtor NavBox, a maritime gateway used for distributing digital charts and navigational data, contains a security flaw that allows unauthorized access to sensitive information. An attacker with network access to the device can retrieve internal configuration details, operational logs, and maritime system identifiers without needing a password. This exposure could allow an adversary to map out shipboard networks or gain insights into vessel operations.
Technical details
A missing authentication vulnerability (CWE-306) exists in the HTTP API of Navtor NavBox. The flaw is located on TCP port 8080, where several endpoints fail to verify user identity before granting access to sensitive data. By sending unauthenticated HTTP GET requests, a remote attacker can extract internal network parameters, Electronic Chart Display and Information System (ECDIS) data, Operational Technology (OT) information, and service logs. Additionally, certain requests may trigger unhandled exceptions that disclose verbose stack traces, further revealing internal application architecture. The vulnerability is addressed in version 4.16.2.4.
Affected products
- Navtor NavBox 4.12.0.3 up to (excluding) 4.16.2.4
Timeline
- 2025-11: patched: Version 4.16.2.4 released
- 2026-03-06: disclosed: Initial NVD publication