NAVTOR NavBox versions 4.16.1.20 and prior contain a hard-coded credentials vulnerability (CVE-2026-21404) within the Windows Communication Foundation (SOAP) implementation. A local attacker can extract these credentials to authenticate against the SOAP interface, gaining access to privileged WCF methods to write or overwrite files within application-defined paths, potentially causing operational disruption.
NAVTOR
1 post
NAVTOR NavBox (CVE-2026-21404)