Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Navtor NavBox exposes internal server information to attackers

CVE-2026-2752
Summary

An attacker can send special requests to Navtor NavBox's /api/ais-data endpoint and get sensitive information about the server's internal workings. This could help the attacker plan a more targeted attack. Update Navtor NavBox to fix this issue.

Original title
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to ret...
Original description
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library references (e.g., System.Data.SQLite), which may assist attackers in mapping the application's internal structure.
nvd CVSS3.1 5.3
Vulnerability type
CWE-209
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026