Information Disclosure Vulnerability in Navtor NavBox by Navtor
CVE-2026-2752

5.3MEDIUM

Key Information:

Vendor

Navtor

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-2752?

The Navtor NavBox is susceptible to an information disclosure vulnerability through its /api/ais-data endpoint. An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests that trigger unhandled exceptions. This causes the server to output verbose .NET stack traces, which may contain sensitive internal details such as class names, method calls, and references to third-party libraries like System.Data.SQLite. This level of detail can assist malicious actors in gaining insights into the underlying architecture of the application, potentially leading to further exploitation.

Affected Version(s)

NavBox 4.12.0.3

NavBox 4.16.2.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cydome Security Ltd
.