← back
CVE-2026-40425mediumCWE-552

MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Parties

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N