Vulnerability in Danelec MacGregor Voyage Data Recorder Web Interface
CVE-2026-40425

6.9MEDIUM

Key Information:

Vendor

Danelec

Vendor
CVE Published:
29 May 2026

What is CVE-2026-40425?

The web interface of the Danelec MacGregor Voyage Data Recorder is susceptible to an improper access control vulnerability. An attacker with administrative access can directly edit sensitive files related to authentication mechanisms, which can potentially allow the modification of the root password. This vulnerability could lead to unauthorized access and control over the device, posing significant risks to operational integrity.

Affected Version(s)

MacGregor Voyage Data Recorder (VDR) G4e 0 < 5.250

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Tierney of Pen Test Partners reported these vulnerabilities to CISA.
.