CVE-2026-40425
Received Received - Intake
Authentication Bypass in Danelec MacGregor VDR

Publication date: 2026-05-29

Last updated on: 2026-05-29

Assigner: ICS-CERT

Description
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-29
Last Modified
2026-05-29
Generated
2026-05-30
AI Q&A
2026-05-29
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
danelec macgregor_voyage_data_recorder *
danelec macgregor_voyage_data_recorder v5.250
danelec csafpid_0001 v5.250
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the administrator account of the Danelec MacGregor Voyage Data Recorder web interface. It allows the administrator to directly edit sensitive files related to authentication, which can potentially lead to changing the root password.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing an administrator with access to the web interface to modify critical authentication files. This could lead to unauthorized changes such as altering the root password, which may compromise system security, enable unauthorized access, and potentially disrupt the normal operation of the device.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows the administrator account of the Danelec MacGregor Voyage Data Recorder web interface to directly edit sensitive authentication files, including potentially changing the root password. This could lead to unauthorized access or modification of sensitive data.

Such unauthorized access and potential compromise of authentication mechanisms can impact the confidentiality and integrity of data, which are critical requirements under common standards and regulations like GDPR and HIPAA.

Therefore, this vulnerability may hinder compliance with these regulations by increasing the risk of unauthorized data access or alteration.


What immediate steps should I take to mitigate this vulnerability?

The vulnerability allows the administrator account of the Danelec MacGregor Voyage Data Recorder web interface to directly edit sensitive authentication files, potentially changing the root password.

Immediate mitigation steps are not explicitly detailed in the provided context or resources.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart