Executive brief
A security vulnerability exists in the Garmin EmpirBus Wireless Display Unit (WDU), a device used for marine electronic system monitoring and control. An attacker on the same local network can trick a user into clicking a malicious link, allowing the attacker to run unauthorized code in the user's browser. This could lead to unauthorized administrative access to the device, potentially allowing the attacker to change system settings or disrupt marine operations.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of Garmin EmpirBus Wireless Display Unit (WDU) v1 (firmware 1.4.6) and v2 (firmware 5.0). The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker on the local network segment can exploit this by inducing a victim to visit a specially crafted URL and interact with a page element. Successful exploitation allows the execution of arbitrary JavaScript in the context of the WDU web interface, which can be leveraged to gain full administrative access to the device. The issue is resolved in WDUv2 firmware version 5.20 and later.
Affected products
- Garmin EmpirBus Wireless Display Unit (WDU) v1 1.4.6
- Garmin EmpirBus Wireless Display Unit (WDU) v2 5.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory
- 2026-04-02: patched: Fixed in WDUv2 software version 5.20