Danelec MacGregor Voyage Data Recorder
web interface can directly edit sensitive files related to authentication, potentially changing the root password.
Project Subscriptions
No data.
No advisories yet.
Solution
Danelec has released firmware version V5.250 to resolve these vulnerabilities. Users of MacGregor Voyage Data Recorder (VDR) G4e devices are encouraged to update the firmware at the earliest service attendance rather than waiting for an annual performance test. Contact Danelec with additional questions: https://www.danelec.com/contact
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. | |
| Title | MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T19:46:13.488Z
Reserved: 2026-05-07T16:55:26.137Z
Link: CVE-2026-40425
Updated: 2026-05-29T19:46:06.830Z
Status : Received
Published: 2026-05-29T19:16:23.673
Modified: 2026-05-29T19:16:23.673
Link: CVE-2026-40425
No data.
OpenCVE Enrichment
Updated: 2026-05-29T19:30:05Z