Junglewise Threat Intelligence

CVE-2025-27851: Garmin EmpirBus WDU Cross-Site WebSocket Hijacking

CVE-2025-27851 · Severity: critical · CVSS 9.3 · Published 2026-05-13

Technologies: Garmin EmpirBus WDU v1, Garmin EmpirBus WDU v2. Vendors: Garmin.

Executive brief

The Garmin EmpirBus Wireless Display Unit (WDU), a device used for marine system monitoring and control, contains a vulnerability that allows an attacker to take full control of the device. By tricking a user into visiting a malicious website while they are connected to the boat's marine network, an attacker can hijack the device's communication channel. This could allow unauthorized changes to administrative settings and critical marine system controls.

Technical details

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the locally served web interface of the Garmin EmpirBus WDU (v1 version 1.4.6 and v2 version 5.00). The application fails to properly validate the 'Origin' header during the WebSocket handshake, allowing a malicious third-party website to establish a cross-origin connection to the device's WebSocket server. If a user on a multihomed host (connected to both the Garmin Marine Network and the internet) visits an attacker-controlled site, the attacker can send commands via WebSockets to modify administrative settings. This results in full device compromise. The issue is addressed in WDUv2 software version 5.41 and later.

Affected products

  • Garmin EmpirBus Wireless Display Unit (WDU) v1 1.4.6
  • Garmin EmpirBus Wireless Display Unit (WDU) v2 5.00

Timeline

  • 2026-04-02: patched: WDUv2 software version 7.00 released; version 5.41 previously fixed the issue.
  • 2026-05-13: disclosed: Initial CVE publication.

References

Related threats