ZeroHour

CVE-2026-68070

moderate

Unauthenticated Root Command Execution in Digital Watchdog VMAX DVR and NVR Lineups

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-68070 is a missing-authentication flaw (CWE-306) in Digital Watchdog's VMAX DVR and NVR video recorder lineups, in which a critical, network-reachable function passes attacker-supplied bytes directly to a system command executed with root privileges. An unauthenticated attacker on an adjacent network (per the CVSS 4.0 attack vector AV:A) can trigger the flaw by sending crafted requests to the vulnerable service on the recorder, without needing credentials or user interaction. Successful exploitation yields full root command execution on the device, allowing the attacker to take complete control of the recorder, its stored video, and any cameras or credentials it manages, and to use the device as a foothold on the surveillance network. The affected products are the Digital Watchdog VMAX DVR and NVR product lineups; the CVE data does not enumerate specific firmware versions, so defenders should consult the ICS-CERT advisory for the exact affected version ranges. Exploitation status is none known: the flaw is not in the CISA KEV catalog and no public proof-of-concept has been published.

What to do: Apply Digital Watchdog firmware updates for VMAX DVRs and NVRs as specified in the ICS-CERT advisory, since affected version ranges are enumerated there. Until patched, isolate surveillance gear on a restricted VLAN and block all untrusted or guest network access to the recorders' management services via firewall rules, as the flaw requires adjacent-network access. Check recorders for signs of compromise, such as unknown accounts, unexpected outbound connections, or modified configuration, and rotate any credentials stored on the devices.

Affected
Digital Watchdog VMAX DVR product lineup
Digital Watchdog VMAX NVR product lineup
Estimated exposure
moderateTens of thousands of deployed VMAX recorders (rough estimate), with fewer directly exploitable from the internet due to the adjacent-network attack vector — Estimated from typical deployment patterns and internet-exposure counts for Digital Watchdog commercial surveillance recorders seen in public device scans; the CVSS AV:A vector means the flaw must be reached from the same network segment,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

Weakness
CWE-306
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Digital Watchdog VMAX DVR and NVR Product Lineups

CISA advisory details six flaws, aggregate CVSS 9.6, giving attackers full control of Digital Watchdog VMAX DVR/NVR surveillance devices.

CISA advisory ICSA-26-258-01 discloses six vulnerabilities affecting all versions of Digital Watchdog VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4, and VG4 recorders, with aggregate CVSS v3 of 9.6. Flaws include an authentication bypass leaking plaintext admin credentials (CVE-2026-68953), hard-coded credentials enabling root FTP access (CVE-2026-66890, CVE-2026-68950), root command execution (CVE-2026-68070), missing authorization on state-changing CGIs (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, live and recorded surveillance access, and a network pivot point. Products are deployed worldwide across commercial facilities, government, healthcare, and transportation sectors.