CVE 5.8 MEDIUM

NAVTOR NavBox Use of Hard-coded Credentials_CVE-2026-21404

5.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Description

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.

Basic Information

ID CVE-2026-21404
Source icscert
Published Jun 4, 2026 at 19:44

Affected Product

Vendor NAVTOR
Product NavBox
Affected Versions NAVTOR NavBox 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.