CVE-2026-40425
- EPSS 0.38%
- Veröffentlicht 29.05.2026 17:47:17
- Zuletzt bearbeitet 03.06.2026 20:54:47
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVE-2026-42929
- EPSS 0.23%
- Veröffentlicht 29.05.2026 17:44:48
- Zuletzt bearbeitet 04.06.2026 18:26:29
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
CVE-2026-44611
- EPSS 0.14%
- Veröffentlicht 29.05.2026 17:42:15
- Zuletzt bearbeitet 04.06.2026 18:30:59
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
CVE-2026-42951
- EPSS 0.17%
- Veröffentlicht 29.05.2026 17:32:11
- Zuletzt bearbeitet 04.06.2026 18:30:26
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.
CVE-2026-42941
- EPSS 0.23%
- Veröffentlicht 29.05.2026 17:27:29
- Zuletzt bearbeitet 04.06.2026 18:27:04
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
CVE-2016-9339
- EPSS 1.71%
- Veröffentlicht 13.02.2017 21:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attack...