CVE-2026-40425
Authentication Bypass in Danelec MacGregor VDR
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| danelec | macgregor_voyage_data_recorder | * |
| danelec | macgregor_voyage_data_recorder | v5.250 |
| danelec | csafpid_0001 | v5.250 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects the administrator account of the Danelec MacGregor Voyage Data Recorder web interface. It allows the administrator to directly edit sensitive files related to authentication, which can potentially lead to changing the root password.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an administrator with access to the web interface to modify critical authentication files. This could lead to unauthorized changes such as altering the root password, which may compromise system security, enable unauthorized access, and potentially disrupt the normal operation of the device.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allows the administrator account of the Danelec MacGregor Voyage Data Recorder web interface to directly edit sensitive authentication files, including potentially changing the root password. This could lead to unauthorized access or modification of sensitive data.
Such unauthorized access and potential compromise of authentication mechanisms can impact the confidentiality and integrity of data, which are critical requirements under common standards and regulations like GDPR and HIPAA.
Therefore, this vulnerability may hinder compliance with these regulations by increasing the risk of unauthorized data access or alteration.
What immediate steps should I take to mitigate this vulnerability?
The vulnerability allows the administrator account of the Danelec MacGregor Voyage Data Recorder web interface to directly edit sensitive authentication files, potentially changing the root password.
Immediate mitigation steps are not explicitly detailed in the provided context or resources.