Junglewise Threat Intelligence

CVE-2026-44611: Danelec MacGregor VDR weak password hashing

CVE-2026-44611 · Severity: medium · CVSS 5.4 · Published 2026-05-29

Technologies: Danelec VDR G4e. Vendors: Danelec.

Executive brief

The Danelec MacGregor Voyage Data Recorder (VDR), which functions as a 'black box' for maritime vessels, uses an insecure method for storing user passwords. This flaw allows an attacker with access to the ship's local network to potentially crack user passwords through automated guessing. If successful, an attacker could gain unauthorized access to the device, compromising the integrity of recorded voyage data.

Technical details

The vulnerability (CWE-916) exists in the password storage mechanism of the MacGregor VDR G4e. The device utilizes a hashing algorithm that imposes a maximum password length and lacks sufficient computational complexity, making it susceptible to offline brute-force or dictionary attacks. An attacker who has already obtained password hashes (e.g., via CVE-2026-42951) and has adjacent network access can exploit this to recover plaintext credentials. This issue is resolved in firmware version V5.250.

Affected products

  • Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250

Timeline

  • 2026-05-28: advisory: CISA ICSA-26-148-01 published
  • 2026-05-29: disclosed: CVE-2026-44611 published to NVD

References

Related threats