ZeroHour

CVE-2026-68950

moderate

Hard-Coded Root FTP Credentials in Digital Watchdog VMAX DVRs/NVRs

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Digital Watchdog VMAX DVR and NVR recorders ship with hard-coded credentials (CWE-798) that can be used to authenticate to the device's ftpd service, which then runs as root. An attacker who can reach the FTP service can log in with these embedded credentials and gain full remote root-level file access to the recorder, including the ability to read, modify, or delete stored video and system files. The CVSS 4.0 vector (AV:A) indicates exploitation requires adjacency — typically an attacker on the same network segment — although any unit with FTP reachable from the internet would be directly exposed. The affected population is the Digital Watchdog VMAX lineup of DVRs and NVRs; the advisory data does not enumerate specific firmware versions. Exploitation status is none known: there is no public PoC and the CVE is not in CISA's KEV catalog.

What to do: Disable or block the FTP service (TCP/21) on all VMAX DVRs and NVRs and restrict management/FTP access to a dedicated, isolated surveillance VLAN with an allow-list. Contact Digital Watchdog for fixed firmware and apply it as soon as an update is released, since no corrected version is identified in the advisory. Review device logs and filesystems for unexpected FTP sessions or modified/deleted video files that could indicate prior abuse of the root account.

Affected
Digital Watchdog VMAX DVR and NVR product lineupsspecific version ranges not enumerated in the advisory data
Estimated exposure
moderatelow thousands to ~10,000 internet-reachable VMAX units; installed base plausibly in the hundreds of thousands of recorders — Digital Watchdog is a mainstream physical-security vendor whose DVRs/NVRs appear in the thousands on internet-wide scan services, while the CVSS adjacent-network vector means most exploitable units are FTP-reachable only from the local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

Weakness
CWE-798
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Digital Watchdog VMAX DVR and NVR Product Lineups

CISA advisory details six flaws, aggregate CVSS 9.6, giving attackers full control of Digital Watchdog VMAX DVR/NVR surveillance devices.

CISA advisory ICSA-26-258-01 discloses six vulnerabilities affecting all versions of Digital Watchdog VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4, and VG4 recorders, with aggregate CVSS v3 of 9.6. Flaws include an authentication bypass leaking plaintext admin credentials (CVE-2026-68953), hard-coded credentials enabling root FTP access (CVE-2026-66890, CVE-2026-68950), root command execution (CVE-2026-68070), missing authorization on state-changing CGIs (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, live and recorded surveillance access, and a network pivot point. Products are deployed worldwide across commercial facilities, government, healthcare, and transportation sectors.