NAVTOR NavBox
CISA warned that NAVTOR NavBox 4.16.1.20 has hard-coded credentials in its SOAP interface, which could let a local attacker access privileged methods.
Intelligence analysis by GPT-5.4 Mini
CISA issued an ICS advisory for NAVTOR NavBox after finding hard-coded credentials in the product’s Windows Communication Foundation SOAP implementation. If the SOAP feature is enabled, a local attacker could bypass the intended transfer workflow and use privileged methods to write or overwrite files in application-defined paths.
CISA found a hidden passcode mistake in a ship software tool called NavBox. If someone already gets inside the computer, they could use that mistake like a master key and mess with files, which could break normal work.
Analysis
What CISA reported
CISA’s advisory covers NAVTOR NavBox version 4.16.1.20 and identifies CVE-2026-21404. The agency says the product contains hard-coded credentials in its Windows Communication Foundation, or SOAP, implementation. If SOAP functionality is enabled, a local attacker can extract those credentials and use them to bypass the intended transfer workflow.
Impact
According to the advisory, successful authentication to the SOAP interface grants access to privileged WCF methods. That access can allow an attacker to write or overwrite files within application-defined paths, which can disrupt operations. CISA rates the issue as medium severity under both CVSS 3.1 and CVSS 4.0.
Fix and exposure
NAVTOR has released a patch in April 2026, and CISA says version 4.17.2.6 and later includes the fix. The advisory also notes that users with an active NavBox connection will automatically stay up to date, so no user action is required in that case.
Mitigation guidance
CISA recommends minimizing network exposure for control system devices, placing control networks behind firewalls, and using VPNs when remote access is necessary. It also reminds organizations to assess operational impact before deploying defensive controls. CISA says it has no report of known public exploitation specifically targeting this vulnerability and notes that the issue is not remotely exploitable, but it still carries high attack complexity only after local access is obtained.
Key points
- CISA issued advisory ICSA-26-155-01 for NAVTOR NavBox.
- The flaw is CVE-2026-21404 and involves hard-coded credentials in SOAP.
- A local attacker could use the issue to reach privileged methods and alter files.
- NAVTOR says version 4.17.2.6 and later contains the fix.
- CISA says there is no known public exploitation and the issue is not remotely exploitable.
NAVTOR says it patched the issue in April 2026, and CISA says version 4.17.2.6 and later includes the fix. If organizations are on the updated version, the exposure should be reduced without extra work for systems with an active NavBox connection.
Systems still running 4.16.1.20 could remain exposed if SOAP is enabled and local access is available. Because the flaw can allow file overwrite actions, abuse could interfere with operations even though it is not remotely exploitable.



