Executive brief
The Danelec MacGregor Voyage Data Recorder (VDR), a device used on maritime vessels to record critical voyage data, contains a default username and password that cannot be changed by the user. An attacker with access to the ship's local network could use these credentials to gain unauthorized administrative access to the device. This could allow them to tamper with recorded data, disrupt operations, or gain a foothold for further attacks on the vessel's systems.
Technical details
The Danelec MacGregor Voyage Data Recorder (VDR) G4e (versions prior to V5.250) is vulnerable to the use of default credentials (CWE-1392). The device ships with a default username and password that are not subject to an enforced change policy upon initial setup. An attacker with adjacent network access can authenticate to the device without prior authorization. Successful exploitation grants the attacker administrative privileges, enabling them to modify configurations or access sensitive voyage data. This vulnerability is part of a larger set of credential-related issues (including hard-coded accounts and insecure password hashing) addressed in firmware version V5.250.
Affected products
- Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250
CVE identifiers
- CVE-2026-40425
- CVE-2026-44611
- CVE-2026-42929
- CVE-2026-42951
- CVE-2026-42941
Timeline
- 2026-05-28: advisory: CISA published advisory ICSA-26-148-01
- 2026-05-29: disclosed: CVE-2026-42941 published to NVD