Default credentials and weak password protections expose MacGregor VDR devices to administrator takeover attacks.
- CISA identifies multiple vulnerabilities in MacGregor Voyage Data Recorder devices used globally
- Flaws include default credentials, weak password hashing, and accessible backup files containing credential data
- Danelec has released firmware version V5.250 to address the security issues
CISA has issued an advisory warning about critical security vulnerabilities in MacGregor Voyage Data Recorder (VDR) G4e devices that could allow attackers to gain administrator access to maritime safety equipment.
The advisory published on 28 May identifies multiple security flaws in Danelec’s MacGregor VDR devices, which are deployed worldwide in the transportation sector. The vulnerabilities affect all MacGregor Voyage Data Recorder G4e versions prior to V5.250.
The most serious flaw, tracked as CVE-2026-42941, involves the use of default credentials with no enforced password change requirement. CISA rates this vulnerability with a CVSS score of 8.3, marking it as high severity. The weakness falls under CWE-1392, which covers the use of default credentials that remain unchanged after deployment.
A second vulnerability, CVE-2026-42951, allows authenticated users to download device backups containing account data and password hashes. This creates additional risk as the downloaded credential information could be used to compromise the system further.
The advisory also notes problems with insufficiently protected credentials, weak password hashing algorithms, hard-coded credentials, and files accessible to external parties. These combined weaknesses create multiple attack vectors that could compromise the integrity of voyage data recording systems.
Voyage Data Recorders serve as maritime “black boxes,” capturing critical navigation and safety information required by international shipping regulations. Compromise of these systems could affect incident investigation capabilities and potentially impact vessel safety operations.
Danelec has released firmware version V5.250 to address these security issues. The company recommends users update their firmware during the next scheduled service attendance rather than waiting for annual performance testing. Additional support is available through Danelec’s contact channels.
Why It Matters
Maritime VDR systems contain sensitive operational data and serve critical safety functions in shipping operations. Successful exploitation could compromise investigation capabilities following maritime incidents and potentially impact vessel safety systems. For organisations operating or managing maritime assets, these vulnerabilities represent both operational and regulatory compliance risks, as VDR systems are mandated by international maritime safety regulations.
What To Do Now
- Identify MacGregor VDR G4e devices in your organisation’s maritime assets and verify firmware versions against the CISA advisory
- Coordinate with vessel operators to schedule firmware updates to version V5.250 during next service attendance
- Contact Danelec directly for technical support and update guidance through their official contact channels
