---
id: CVE-2026-21404
title: >-
  NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within
  its Windows Communication Foundation (SOAP) implementation
summary: >-
  NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within
  its Windows Communication Foundation (SOAP) implementation. If the SOAP
  functionality is enabled, a local attacker can extract credentials to bypass
  the inten…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-798
vendor: navtor
product: navbox_firmware
affected:
  - navbox_firmware <= 4.16.1.20
published: '2026-06-04'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21404'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-155-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.01713
ingestedAt: '2026-07-16T02:48:55.070Z'
---

## Overview

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.

## Affected

- `navbox_firmware <= 4.16.1.20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
