Executive brief
The Danelec MacGregor Voyage Data Recorder (VDR), a device used to record vessel data for maritime safety and investigations, contains a security flaw in its web management interface. An authorized administrator can directly modify sensitive system files, which could allow them to change the root password and gain deeper control over the device. This could lead to unauthorized access to recorded voyage data or interference with the device's operations.
Technical details
A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in the Danelec MacGregor Voyage Data Recorder (VDR) G4e. The web interface allows users with administrative privileges to directly modify sensitive system files related to authentication. An attacker with high privileges and adjacent network access could exploit this to change the root password, potentially escalating their control over the underlying operating system. This issue is resolved in firmware version V5.250.
Affected products
- Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250
Timeline
- 2026-05-28: advisory: CISA ICSA-26-148-01 published
- 2026-05-29: disclosed: CVE published to NVD
- 2026-05-28: patched: Firmware V5.250 released by vendor