Vulnerability in Danelec MacGregor Voyage Data Recorder Web Interface
CVE-2026-40425
6.9MEDIUM
What is CVE-2026-40425?
The web interface of the Danelec MacGregor Voyage Data Recorder is susceptible to an improper access control vulnerability. An attacker with administrative access can directly edit sensitive files related to authentication mechanisms, which can potentially allow the modification of the root password. This vulnerability could lead to unauthorized access and control over the device, posing significant risks to operational integrity.
Affected Version(s)
MacGregor Voyage Data Recorder (VDR) G4e 0 < 5.250
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew Tierney of Pen Test Partners reported these vulnerabilities to CISA.
