


Perceptive Security
SOC/SIEM Consultancy

Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 20:03:36
Source:
nvd.nist.gov
Critical Infrastructure, Mobile & IoT
CVE-2026-42929 affects Danelec MacGregor Voyage Data Recorder systems which include default accounts with hard-coded credentials. This vulnerability allows unauthorized access to maritime voyage data recording systems through the use of default authentication credentials that are built into the product. The issue represents a significant security risk for maritime operations as these systems record critical navigation and operational data. CISA has issued an advisory (ICSA-26-148-01) addressing this vulnerability. The vulnerability impacts critical maritime infrastructure used for compliance and safety purposes.
Technical details
Mitigation steps:
Affected products:
Danelec MacGregor Voyage Data Recorder
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42929
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-01.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01
https://www.danelec.com/contact
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
