216.73.217.22

CVE-2026-2754

· Published 06/03/2026 15:16 · Modified 06/03/2026 15:16

Labels: CVE-2026-2754 2026-03-0656a186b1-7f5e-4314-ba38-38d5499fccfdCVE-2026-2754CWE-306

Essential information

Published
06/03/2026 15:16
Modified
06/03/2026 15:16
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT Information, device identifiers, and service status logs.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
56a186b1-7f5e-4314-ba38-38d5499fccfd
NVD
View on NVD

Affected products (CPE)

ProductCPE
navtor / navbox cpe:2.3:a:navtor:navbox:*:*:*:*:*:*:*:*

References