PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40425 Danelec CVE debrief

A medium-severity vulnerability in the Danelec MacGregor Voyage Data Recorder (VDR) web interface allows an authenticated administrator to directly edit sensitive authentication-related files, with potential for root password modification. The vulnerability stems from improper access controls (CWE-552) that fail to restrict file editing capabilities to appropriate security boundaries. The CVSS 4.0 vector indicates attack vector is adjacent network, low attack complexity, high privileges required, with high confidentiality impact and low integrity/availability impacts. This is an industrial control systems vulnerability affecting maritime safety equipment, published by CISA ICS-CERT on May 29, 2026.

Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Maritime operators, ship owners, and fleet managers utilizing Danelec MacGregor VDR systems; industrial cybersecurity teams responsible for OT/ICS environments; port authorities and classification societies auditing vessel cybersecurity compliance; system integrators deploying maritime safety equipment.

Technical summary

The Danelec MacGregor Voyage Data Recorder web interface implements insufficient access controls on sensitive system files. An administrator-level authenticated user can directly modify files containing authentication credentials, including the potential to change the root password. The vulnerability is classified under CWE-552 (Files or Directories Accessible to External Parties). Attack requires adjacent network access and high privileges, with CVSS 4.0 score of 6.9 (Medium). Confidentiality impact is rated high, while integrity and availability impacts are low. This affects maritime safety-critical systems where VDRs are mandated for vessel voyage data recording.

Defensive priority

medium

Recommended defensive actions

  • Restrict administrative access to the VDR web interface to trusted network segments only
  • Implement network segmentation to isolate VDR systems from untrusted networks
  • Monitor file system changes to authentication-related files on VDR systems
  • Apply vendor patches when available per CISA ICS-CERT guidance
  • Review and enforce principle of least privilege for administrative accounts
  • Contact Danelec for specific remediation guidance and patch availability

Evidence notes

Vulnerability disclosed via CISA ICS-CERT advisory ICSA-26-148-01. CVSS 4.0 vector provided by NVD. Weakness classified as CWE-552 (Files or Directories Accessible to External Parties). Vendor contact information available through Danelec official channels.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40425 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40425

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40425 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40425

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.