MEDIUM · 5.7

CVE-2026-40425

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

Vulnerability Description

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
MacgregorInterschalt Vdr G4E Firmware< 5.250
MacgregorInterschalt Vdr G4E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-40425?

CVE-2026-40425 is a vulnerability with a CVSS score of 5.7 (MEDIUM). The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

How severe is CVE-2026-40425?

CVE-2026-40425 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-40425?

Check the references section above for vendor advisories and patch information. Affected products include: Macgregor Interschalt Vdr G4E Firmware, Macgregor Interschalt Vdr G4E.