Information Disclosure Vulnerability in Navtor NavBox by Navtor
CVE-2026-2752
5.3MEDIUM
What is CVE-2026-2752?
The Navtor NavBox is susceptible to an information disclosure vulnerability through its /api/ais-data endpoint. An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests that trigger unhandled exceptions. This causes the server to output verbose .NET stack traces, which may contain sensitive internal details such as class names, method calls, and references to third-party libraries like System.Data.SQLite. This level of detail can assist malicious actors in gaining insights into the underlying architecture of the application, potentially leading to further exploitation.
Affected Version(s)
NavBox 4.12.0.3
NavBox 4.16.2.4
