CVE-2026-40425

MEDIUM

MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties

Title source: cna
STIX 2.1

Description

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

Scores

CVSS v3 5.7
EPSS 0.0060
EPSS Percentile 43.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (2)
Danelec/MacGregor Voyage Data Recorder (VDR) G4e < 5.250
macgregor/interschalt_vdr_g4e_firmware < 5.250
Published May 29, 2026
Tracked Since May 30, 2026