Executive brief
The Garmin EmpirBus Wireless Display Unit (WDU), a device used for marine digital switching and monitoring, contains a security flaw in its local web interface. An attacker can bypass the login screen to gain unauthorized access to the device's control functions and data. This could allow an unauthorized user on the network to interfere with vessel monitoring systems or change device settings.
Technical details
A missing authentication vulnerability (CWE-306) exists in the Garmin EmpirBus Wireless Display Unit (WDU) v1 (firmware 1.4.6) and v2 (firmware 5.0). While the web interface implements a client-side authentication check in the browser, the backend WebSocket server does not enforce any authentication for incoming requests. A remote attacker can bypass all authentication mechanisms by directly interacting with the remote APIs available via the WebSocket. This allows for unauthorized read and write access to device functions. The issue is addressed in WDUv2 software version 5.41 and later.
Affected products
- Garmin EmpirBus Wireless Display Unit (WDU) v1 firmware 1.4.6
- Garmin EmpirBus Wireless Display Unit (WDU) v2 firmware 5.00
Timeline
- 2025-05-13: disclosed
- 2026-04-02: patched: Fixed in WDUv2 software version 5.41
- 2026-05-13: advisory