CVE-2026-40425
Analyzed
Analyzed - Analysis Complete
Authentication Bypass in Danelec MacGregor VDR
Publication date: 2026-05-29
Last updated on: 2026-06-03
Assigner: ICS-CERT
Description
Description
The administrator account for the
Danelec MacGregor Voyage Data Recorder
web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| macgregor | interschalt_vdr_g4e_firmware | to 5.250 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |