CVE-2026-44611
Published May 29, 2026Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
- evidence mentions
- 3
- Buzz score
- 25.4
Vendor/product archive
6 CVEs tagged to macgregor / interschalt_vdr_g4e — 0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root…
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutr…