Junglewise Threat Intelligence

CVE-2026-40425: Danelec MacGregor VDR use of default credentials

CVE-2026-40425 · Severity: high · CVSS 8.3 · Published 2026-05-29

Technologies: Danelec VDR G4e. Vendors: Danelec.

Executive brief

The Danelec MacGregor Voyage Data Recorder (VDR), a device used on maritime vessels to record critical voyage data, contains a default username and password that cannot be changed by the user. An attacker with access to the ship's local network could use these credentials to gain unauthorized administrative access to the device. This could allow them to tamper with recorded data, disrupt operations, or gain a foothold for further attacks on the vessel's systems.

Technical details

The Danelec MacGregor Voyage Data Recorder (VDR) G4e (versions prior to V5.250) is vulnerable to the use of default credentials (CWE-1392). The device ships with a default username and password that are not subject to an enforced change policy upon initial setup. An attacker with adjacent network access can authenticate to the device without prior authorization. Successful exploitation grants the attacker administrative privileges, enabling them to modify configurations or access sensitive voyage data. This vulnerability is part of a larger set of credential-related issues (including hard-coded accounts and insecure password hashing) addressed in firmware version V5.250.

Affected products

  • Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250

CVE identifiers

  • CVE-2026-40425
  • CVE-2026-44611
  • CVE-2026-42929
  • CVE-2026-42951
  • CVE-2026-42941

Timeline

  • 2026-05-28: advisory: CISA published advisory ICSA-26-148-01
  • 2026-05-29: disclosed: CVE-2026-42941 published to NVD

References

Related threats