Junglewise Threat Intelligence

CVE-2026-42951: Danelec MacGregor VDR credential exposure in device backup

CVE-2026-42951 · Severity: medium · CVSS 5.4 · Published 2026-05-29

Technologies: Danelec VDR G4e. Vendors: Danelec.

Executive brief

The Danelec MacGregor Voyage Data Recorder (VDR), a device used on maritime vessels to record data for accident investigation, contains a vulnerability where authenticated users can download system backups. These backups contain sensitive account information and password hashes. If exploited, an attacker with low-level access could obtain credentials to gain full administrative control over the device, potentially compromising the integrity of recorded voyage data.

Technical details

The Danelec MacGregor Voyage Data Recorder (VDR) G4e suffers from an insufficiently protected credentials vulnerability (CWE-522). An authenticated user with low privileges can trigger a backup download of the device. This backup file contains sensitive configuration data, including user account details and password hashes. Because the attack requires adjacent network access and specific timing or configuration conditions (reflected in the High Attack Complexity), the CVSS score is moderated. Successful exploitation allows an attacker to perform offline brute-force attacks on the hashes to escalate privileges to an administrator level. The vulnerability is resolved in firmware version V5.250.

Affected products

  • Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250

Timeline

  • 2026-05-28: advisory: CISA ICS Advisory ICSA-26-148-01 published
  • 2026-05-29: disclosed: CVE-2026-42951 published to NVD

References

Related threats