Security/ security · maritime · ics · credentials

Maritime Black Boxes Shipped With Hard-coded Credentials

Five flaws in Danelec's widely deployed voyage data recorders gave network-adjacent attackers a clear path to administrator access.

Maritime Black Boxes Shipped With Hard-coded Credentials

Five security flaws in Danelec's MacGregor VDR G4e give an attacker on the same network a direct path to full device control.

Danelec, a Danish manufacturer, shipped the G4e with default credentials and no enforced password change, alongside hard-coded accounts baked into the firmware. The password hashing scheme was weak enough to crack by brute force, and an authenticated user could download a full device backup containing account data and password hashes. The web interface also let administrators edit authentication files directly, including the root password. All five were patched in firmware V5.250, released after researcher Andrew Tierney of Pen Test Partners reported them to CISA.

Voyage data recorders are the maritime equivalent of flight data recorders. They log navigation data, radar feeds, audio, and sensor readings, and are routinely used as evidence after accidents at sea. Administrator access means an attacker could alter or delete that record before investigators arrive. The advisory recommends operators update "at earliest service attendance" rather than waiting for annual tests, which suggests a patch cadence measured in months for this class of device.

The attack vector is adjacent network, not the open internet. An attacker must already be aboard or connected to the vessel's systems, which is a narrower threat than a remote exploit. For high-value commercial shipping, it is not a theoretical one.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →