Skip to main content
Mallory
High

Hard-coded Default Credentials in Danelec MacGregor Voyage Data Recorder

IdentifiersCVE-2026-42929CWE-798· Use of Hard-coded Credentials

CVE-2026-42929 affects the Danelec MacGregor Voyage Data Recorder. The available information indicates that the product includes default accounts with hard-coded credentials. This means one or more built-in accounts use credentials embedded in the product and not intended to be changed or fully managed by the operator, enabling authentication with known or fixed credentials. No specific vulnerable component, service, or function is identified in the provided material.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to authenticate to the affected voyage data recorder using hard-coded default credentials and obtain unauthorized access. Based on the provided scoring and advisory summary, the primary impacts are high confidentiality and high integrity impact, with low availability impact. This could enable unauthorized access to stored or accessible data and unauthorized modification of system state or recorder-related information.

Mitigation

If you can’t patch tonight, do this now.

Until a vendor fix is applied, restrict network access to the Voyage Data Recorder to only trusted management networks and authorized hosts, especially because the CVSS vector indicates adjacent-network reachability. Isolate the device from untrusted or shared networks, monitor for authentication attempts using known/default accounts, disable or remove default accounts if the platform permits, and enforce compensating controls such as network segmentation and strict access control lists.

Remediation

Patch, then assume compromise.

Apply the vendor-provided fix or updated product version referenced by the relevant CISA ICS advisory for CVE-2026-42929 / ICSA-26-148-01 when available from Danelec. Because the issue is the presence of hard-coded default credentials, remediation requires eliminating those credentials from the product or replacing them with unique, changeable credentials under operator control.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
MacgregorInterschalt Vdr G4e Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.