ZeroHour

CVE-2026-66887

moderate

Unauthenticated State-Changing CGI Access in Digital Watchdog VMAX DVR/NVR

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

Digital Watchdog VMAX DVRs and NVRs are missing authorization checks on state-changing CGI endpoints and perform no session validation, so requests that modify device state can be accepted without a valid authenticated session (CWE-862). An attacker who can reach the recorder on the same network segment (CVSS attack vector is adjacent-network, with no privileges or user interaction required) can invoke these CGIs directly and change device configuration or behavior, with critical-rated impacts on the confidentiality, integrity, and availability of the recorder and dependent systems such as recorded video and surveillance operations. Organizations running VMAX DVR/NVR appliances — typically commercial and physical-security video deployments — are affected. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and there is no evidence of exploitation in the wild, though exposed recorder web interfaces are routine targets once network access is obtained.

What to do: Apply the vendor firmware update for the VMAX DVR/NVR lineups as described in the ICS-CERT advisory and confirm the patched build is running. Because exploitation requires adjacent-network access, place recorders on a dedicated VLAN or behind firewall rules so only trusted clients can reach their CGI/web endpoints. Rotate any default credentials and review device logs for unexpected configuration changes or CGI requests.

Affected
Digital Watchdog VMAX DVR
Digital Watchdog VMAX NVR
Estimated exposure
moderate≈ low thousands of internet-reachable VMAX units, plus a larger uncounted on-premises installed base — Public internet scans (Shodan/Censys-type) typically show low-thousands counts of exposed Digital Watchdog/VMAX recorder web interfaces, and these appliances are widely deployed across the SMB and commercial surveillance market; no exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

Weakness
CWE-862
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Digital Watchdog VMAX DVR and NVR Product Lineups

CISA advisory details six flaws, aggregate CVSS 9.6, giving attackers full control of Digital Watchdog VMAX DVR/NVR surveillance devices.

CISA advisory ICSA-26-258-01 discloses six vulnerabilities affecting all versions of Digital Watchdog VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4, and VG4 recorders, with aggregate CVSS v3 of 9.6. Flaws include an authentication bypass leaking plaintext admin credentials (CVE-2026-68953), hard-coded credentials enabling root FTP access (CVE-2026-66890, CVE-2026-68950), root command execution (CVE-2026-68070), missing authorization on state-changing CGIs (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, live and recorded surveillance access, and a network pivot point. Products are deployed worldwide across commercial facilities, government, healthcare, and transportation sectors.