PatchSiren cyber security CVE debrief
CVE-2026-40425 Danelec CVE debrief
A medium-severity vulnerability in the Danelec MacGregor Voyage Data Recorder (VDR) web interface allows an authenticated administrator to directly edit sensitive authentication-related files, with potential for root password modification. The vulnerability stems from improper access controls (CWE-552) that fail to restrict file editing capabilities to appropriate security boundaries. The CVSS 4.0 vector indicates attack vector is adjacent network, low attack complexity, high privileges required, with high confidentiality impact and low integrity/availability impacts. This is an industrial control systems vulnerability affecting maritime safety equipment, published by CISA ICS-CERT on May 29, 2026.
- Vendor
- Danelec
- Product
- MacGregor Voyage Data Recorder (VDR) G4e
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-05-29
Who should care
Maritime operators, ship owners, and fleet managers utilizing Danelec MacGregor VDR systems; industrial cybersecurity teams responsible for OT/ICS environments; port authorities and classification societies auditing vessel cybersecurity compliance; system integrators deploying maritime safety equipment.
Technical summary
The Danelec MacGregor Voyage Data Recorder web interface implements insufficient access controls on sensitive system files. An administrator-level authenticated user can directly modify files containing authentication credentials, including the potential to change the root password. The vulnerability is classified under CWE-552 (Files or Directories Accessible to External Parties). Attack requires adjacent network access and high privileges, with CVSS 4.0 score of 6.9 (Medium). Confidentiality impact is rated high, while integrity and availability impacts are low. This affects maritime safety-critical systems where VDRs are mandated for vessel voyage data recording.
Defensive priority
medium
Recommended defensive actions
- Restrict administrative access to the VDR web interface to trusted network segments only
- Implement network segmentation to isolate VDR systems from untrusted networks
- Monitor file system changes to authentication-related files on VDR systems
- Apply vendor patches when available per CISA ICS-CERT guidance
- Review and enforce principle of least privilege for administrative accounts
- Contact Danelec for specific remediation guidance and patch availability
Evidence notes
Vulnerability disclosed via CISA ICS-CERT advisory ICSA-26-148-01. CVSS 4.0 vector provided by NVD. Weakness classified as CWE-552 (Files or Directories Accessible to External Parties). Vendor contact information available through Danelec official channels.
Official resources
2026-05-29