NAVTOR has undertaken a widespread patching programme for its NavBox vessel data gateway after three security vulnerabilities affecting the equipment were discovered and disclosed by cyber security firm Cydome.
The vulnerabilities, identified in version 4.12.0.3, could have potentially allowed unauthorised remote access to vessel telemetry, network configurations, and data from Electronic Chart Display and Information Systems (ECDIS).
The three identified Common Vulnerabilities and Exposures (CVE) include missing authentication on API endpoints, an absolute path traversal vulnerability, and an information disclosure vulnerability. These issues could allow an attacker to retrieve network information or arbitrary files from the host operating system.
NAVTOR confirmed that the issues have been remediated in NavBox version 4.16.2.4 and later. The company stated that affected customers were notified prior to the publication of the CVEs and that devices with an active online connection have been automatically updated.
“At NAVTOR, we are committed to maintaining the highest standards of product security, and welcome good‑faith security research and coordinated vulnerability disclosure. Following Cydome’s responsible report, we verified the three findings and confirmed they impacted legacy NavBox v4.12.0.3,” said Tyr Steffensen, Cyber Security Officer, NAVTOR.
“The issues have been remediated as follows: CVE‑2026‑2753 was remediated in NavBox v4.14.1.2 and later (released late 2024), while CVE‑2026‑2752 and CVE‑2026‑2754 were remediated in NavBox v4.16.2.4 and later (released November 2025).”
“Affected customers have been contacted individually. Customers with an active, online NavBox have been patched since late 2024 for CVE‑2026‑2753 and since November 2025 for CVE‑2026‑2752 and CVE‑2026‑2754. Customers can rest assured that all NavBoxes with an active online connection are automatically kept up to date with the latest version. We thank Cydome for identifying these vulnerabilities and for the responsible disclosure.”
The findings come amid a reported 150 per cent increase in cyberattacks targeting maritime Operational Technology (OT) over the past year. According to Cydome, 50 per cent of OT incidents begin with unauthorised external access, often accelerated by generative artificial intelligence (AI) technologies used to exploit devices.
“Shipping companies are currently facing a significant gap,” said Nir Ayalon, Chief Executive Officer of Cydome.
“While their fleets become more connected with Low Earth Orbit (LEO) broadband service, their OT devices are more exposed than ever to cyber threats.”



