Junglewise Threat Intelligence

CVE-2026-40425: Danelec MacGregor VDR G4e File Access in Web Interface

CVE-2026-40425 · Severity: medium · CVSS 5.7 · Published 2026-05-29

Technologies: Danelec VDR G4e. Vendors: Danelec.

Executive brief

The Danelec MacGregor Voyage Data Recorder (VDR), a device used to record vessel data for maritime safety and investigations, contains a security flaw in its web management interface. An authorized administrator can directly modify sensitive system files, which could allow them to change the root password and gain deeper control over the device. This could lead to unauthorized access to recorded voyage data or interference with the device's operations.

Technical details

A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in the Danelec MacGregor Voyage Data Recorder (VDR) G4e. The web interface allows users with administrative privileges to directly modify sensitive system files related to authentication. An attacker with high privileges and adjacent network access could exploit this to change the root password, potentially escalating their control over the underlying operating system. This issue is resolved in firmware version V5.250.

Affected products

  • Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250

Timeline

  • 2026-05-28: advisory: CISA ICSA-26-148-01 published
  • 2026-05-29: disclosed: CVE published to NVD
  • 2026-05-28: patched: Firmware V5.250 released by vendor

References

Related threats