ZeroHour

CVE-2026-66890

moderate

Hard-Coded FTP Credentials Give Root File Access in Digital Watchdog VMAX DVRs/NVRs

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

Digital Watchdog VMAX DVR and NVR recorders ship with hard-coded credentials baked into the firmware, in violation of secure development practice (CWE-798). When the device's FTP service is reachable, a remote attacker can authenticate using these embedded credentials and access files with root privileges, potentially reading or modifying arbitrary files on the recorder, including stored video footage and configuration data. The CVSS 4.0 base score is 9.4 (critical), though the adjacent-network attack vector means the attacker generally needs access to the same network segment as the recorder. The affected population is the Digital Watchdog VMAX lineup of DVRs and NVRs, which are commonly deployed in commercial video surveillance environments such as retail, banking, and education. There is no known public proof-of-concept and no evidence of in-the-wild exploitation to date.

What to do: Apply vendor firmware updates to affected VMAX DVRs/NVRs as soon as Digital Watchdog releases them, and check the ICS-CERT advisory for the exact model and firmware list. Immediately disable the FTP service if it is not required, and restrict management protocols on recorders to a dedicated VLAN or firewall allowlist so only trusted clients can reach them. Audit FTP access logs for unauthorized logins and rotate any local credentials as a precaution.

Affected
Digital Watchdog (DW) VMAX DVR lineup
Digital Watchdog (DW) VMAX NVR lineup
Estimated exposure
moderate≈tens of thousands of VMAX units deployed worldwide, with a subset (likely low thousands) having FTP reachable — Digital Watchdog VMAX recorders are a common commercial surveillance line, and public internet scans historically show thousands of exposed VMAX devices; the adjacent-network vector and the need for FTP to be reachable further limit the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

Weakness
CWE-798
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Digital Watchdog VMAX DVR and NVR Product Lineups

CISA advisory details six flaws, aggregate CVSS 9.6, giving attackers full control of Digital Watchdog VMAX DVR/NVR surveillance devices.

CISA advisory ICSA-26-258-01 discloses six vulnerabilities affecting all versions of Digital Watchdog VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4, and VG4 recorders, with aggregate CVSS v3 of 9.6. Flaws include an authentication bypass leaking plaintext admin credentials (CVE-2026-68953), hard-coded credentials enabling root FTP access (CVE-2026-66890, CVE-2026-68950), root command execution (CVE-2026-68070), missing authorization on state-changing CGIs (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, live and recorded surveillance access, and a network pivot point. Products are deployed worldwide across commercial facilities, government, healthcare, and transportation sectors.