Executive brief
Danelec MacGregor Voyage Data Recorders, which function like 'black boxes' for maritime vessels to record navigation and sensor data, contain default accounts with hard-coded passwords. An attacker with access to the ship's local network could use these credentials to gain unauthorized access to the device. This could allow them to tamper with recorded voyage data or disrupt the operation of critical maritime safety equipment.
Technical details
The MacGregor Voyage Data Recorder (VDR) G4e contains a vulnerability classified as Use of Hard-coded Credentials (CWE-798). The device includes default accounts with credentials that are hard-coded into the firmware and cannot be changed by the user. An attacker with adjacent network access (e.g., on the same vessel network) can use these credentials to authenticate to the device without prior authorization. Successful exploitation grants the attacker administrative access, enabling them to modify sensitive configuration files, access recorded data, or impact the availability of the VDR. This issue is resolved in firmware version V5.250.
Affected products
- Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250
Timeline
- 2026-05-28: advisory: CISA published advisory ICSA-26-148-01
- 2026-05-29: disclosed: CVE-2026-42929 published to NVD