PT-2026-23717 · Navtor · Navtor Navbox
Published
2026-03-06
·
Updated
2026-03-06
·
CVE-2026-2753
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Navtor NavBox (affected versions not specified)
Description
An Absolute Path Traversal issue exists in Navtor NavBox. The application’s HTTP service does not properly sanitize user-supplied path input. Remote attackers can exploit this by submitting requests containing absolute filesystem paths. Successful exploitation allows retrieval of arbitrary files from the filesystem, limited by the service process privileges. This can expose sensitive configuration files and system information. The vulnerability involves improper handling of user-supplied paths, potentially through a vulnerable parameter or variable.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Navtor Navbox