5.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Description
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.
Basic Information
ID
CVE-2026-21404
Source
icscert
Published
Jun 4, 2026 at 19:44
Affected Product
Vendor
NAVTOR
Product
NavBox
Affected Versions
NAVTOR NavBox 0