Unauthenticated Root Command Execution in Digital Watchdog VMAX DVR and NVR Lineups
AI analysis
CVE-2026-68070 is a missing-authentication flaw (CWE-306) in Digital Watchdog's VMAX DVR and NVR video recorder lineups, in which a critical, network-reachable function passes attacker-supplied bytes directly to a system command executed with root privileges. An unauthenticated attacker on an adjacent network (per the CVSS 4.0 attack vector AV:A) can trigger the flaw by sending crafted requests to the vulnerable service on the recorder, without needing credentials or user interaction. Successful exploitation yields full root command execution on the device, allowing the attacker to take complete control of the recorder, its stored video, and any cameras or credentials it manages, and to use the device as a foothold on the surveillance network. The affected products are the Digital Watchdog VMAX DVR and NVR product lineups; the CVE data does not enumerate specific firmware versions, so defenders should consult the ICS-CERT advisory for the exact affected version ranges. Exploitation status is none known: the flaw is not in the CISA KEV catalog and no public proof-of-concept has been published.
What to do: Apply Digital Watchdog firmware updates for VMAX DVRs and NVRs as specified in the ICS-CERT advisory, since affected version ranges are enumerated there. Until patched, isolate surveillance gear on a restricted VLAN and block all untrusted or guest network access to the recorders' management services via firewall rules, as the flaw requires adjacent-network access. Check recorders for signs of compromise, such as unknown accounts, unexpected outbound connections, or modified configuration, and rotate any credentials stored on the devices.
Affected
| Digital Watchdog VMAX DVR product lineup | — |
| Digital Watchdog VMAX NVR product lineup | — |
Estimated exposure
moderateTens of thousands of deployed VMAX recorders (rough estimate), with fewer directly exploitable from the internet due to the adjacent-network attack vector — Estimated from typical deployment patterns and internet-exposure counts for Digital Watchdog commercial surveillance recorders seen in public device scans; the CVSS AV:A vector means the flaw must be reached from the same network segment,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.