Vulnerability Description
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Macgregor | Interschalt Vdr G4E Firmware | < 5.250 |
| Macgregor | Interschalt Vdr G4E | - |
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-14Issue Tracking
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01Third Party AdvisoryUS Government Resource
- https://www.danelec.com/contactProduct
FAQ
What is CVE-2026-40425?
CVE-2026-40425 is a vulnerability with a CVSS score of 5.7 (MEDIUM). The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
How severe is CVE-2026-40425?
CVE-2026-40425 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40425?
Check the references section above for vendor advisories and patch information. Affected products include: Macgregor Interschalt Vdr G4E Firmware, Macgregor Interschalt Vdr G4E.