CVE-2026-21404

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:navtor:navbox_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:navtor:navbox:-:*:*:*:*:*:*:*

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) NAVTOR NavBox hasta la versión 4.16.1.20 contiene credenciales codificadas de forma rígida dentro de su implementación de Windows Communication Foundation (SOAP). Si la funcionalidad SOAP está habilitada, un atacante local puede extraer credenciales para eludir el flujo de trabajo de transferencia previsto. La autenticación exitosa contra la interfaz SOAP otorga acceso a métodos WCF privilegiados, permitiendo a un atacante escribir o sobrescribir archivos dentro de rutas definidas por la aplicación.

15 Jul 2026, 15:24

Type Values Removed Values Added
References () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-155-01.json - () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-155-01.json - Third Party Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01 - Mitigation, US Government Resource
First Time Navtor navbox Firmware
Navtor
Navtor navbox
CPE cpe:2.3:h:navtor:navbox:-:*:*:*:*:*:*:*
cpe:2.3:o:navtor:navbox_firmware:*:*:*:*:*:*:*:*

04 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 20:16

Updated : 2026-07-22 20:10


NVD link : CVE-2026-21404

Mitre link : CVE-2026-21404

CVE.ORG link : CVE-2026-21404


JSON object : View

Products Affected

navtor

  • navbox_firmware
  • navbox
CWE
CWE-798

Use of Hard-coded Credentials