VORANT. Threat Intelligence Sign in Get the full feed

CISA discloses five vulnerabilities in MacGregor VDR G4e maritime devices allowing…

high vulnerability transportation

CISA discloses five vulnerabilities in MacGregor VDR G4e maritime devices allowing attackers to gain admin access via default credentials and weak authentication.

CISA has published an advisory detailing five authentication-related vulnerabilities in Danelec MacGregor Voyage Data Recorder (VDR) G4e devices used in maritime transportation systems worldwide. The vulnerabilities include default and hard-coded credentials that are not required to be changed (CVE-2026-42941, CVE-2026-42929), exposure of password hashes through device backups (CVE-2026-42951), use of weak password hashing algorithms susceptible to brute force (CVE-2026-44611), and insufficient file access controls allowing administrators to directly modify authentication files including the root password (CVE-2026-40425).

Successful exploitation of these vulnerabilities could allow an attacker to gain administrator-level access to the VDR device. All versions prior to V5.250 are affected. Danelec has released firmware version V5.250 to address these issues and recommends users update at the earliest service attendance rather than waiting for annual performance testing.

The vulnerabilities were discovered and reported by Andrew Tierney of Pen Test Partners. CISA recommends standard ICS security practices including network segmentation, minimizing internet exposure, and use of VPNs for remote access. No known public exploitation has been reported to CISA at this time.

Mentioned in this report

Vulnerabilities CVE-2026-40425CVE-2026-42929CVE-2026-42941CVE-2026-42951CVE-2026-44611

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free