NAVTOR Addresses Security Flaws in NavBox Devices Following Cydome's Findings

NAVTOR Addresses Security Flaws in NavBox Devices Following Cydome's Findings

First seen 11 Mar 2026, 18:15 UTC SmartmaritimenetworkSplash247Tech.Einnews 60.6

Article Content

Browse articles
ThreatCluster

Cydome Research has identified multiple security vulnerabilities in NAVTOR's NavBox devices, specifically CVE-2026-2752 and CVE-2026-2754. These vulnerabilities could potentially allow unauthorized access to sensitive vessel data. In response, NAVTOR has initiated a comprehensive patching program to remediate these issues, with updates released in November 2025. The vulnerabilities affect the NavBox vessel data gateway, which is critical for maritime operations. NAVTOR confirmed that the patches are now available and encouraged users to update their systems. The vulnerabilities were disclosed on March 10, 2026, prompting immediate action from NAVTOR. The situation highlights the ongoing need for vigilance in maritime cybersecurity.

Key Points: • Cydome identified critical vulnerabilities CVE-2026-2752 and CVE-2026-2754 in NAVTOR NavBox devices. • NAVTOR has released patches to address these vulnerabilities as part of a broader security initiative. • The vulnerabilities pose risks to vessel data security, necessitating immediate updates from users.

Timeline

2025-11-01
NAVTOR releases NavBox v4.16.2.4 with CVE patches
2026-03-10
Cydome discloses vulnerabilities in NAVTOR NavBox devices
2026-03-11
NAVTOR confirms patch program for NavBox vulnerabilities