ZeroHour

CVE-2026-87827

large

Unauthenticated System Command Execution in KGUARD DVR Firmware

CVSS 4.0
10.0 critical
EPSS
Published
()
Modified
AI analysis

Vulnerable KGUARD DVR firmware runs a system command execution service on all network interfaces (0.0.0.0) without requiring authentication, so any remote attacker with network access to the exposed service can execute arbitrary system commands on the device. Full control of the DVR is the outcome, and the Mirai_ptea (Rimasuta) and Mirai_aurora botnets have already leveraged the flaw to propagate and conduct DDoS activity. Affected devices are primarily those running 2016-era firmware across numerous KGUARD models (D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, and the D97xx, D98xx, and D99xx series, across several hardware revisions); firmware released after 2017 mitigates the issue by binding the service to the localhost interface (127.0.0.1). Exploitation is confirmed in the wild in 2026, including via the rapperbot malware family, and this CVE was assigned specifically to document active exploitation given the lack of vendor documentation. The flaw carries a CVSS v4.0 score of 10 (critical), has no known public proof-of-concept, and is not yet in CISA KEV.

What to do: Upgrade affected KGUARD DVRs to firmware released after 2017, which binds the command execution service to 127.0.0.1; where an update is not possible, remove port-forwarding or firewall rules that expose the DVR's service to the internet and restrict access to trusted hosts only. Check whether the command execution service is listening on 0.0.0.0 rather than localhost, and since these devices are being used for DDoS propagation, monitor for suspicious outbound traffic and reboot or quarantine any unit suspected of compromise.

Affected
KGUARD DVR firmware — D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, and D97xx, D98xx, D99xx sefirmware dating from 2016 is affected; firmware released after 2017 mitigates the issue by restricting the service to 127.0.0.1
Estimated exposure
largetens of thousands of internet-exposed KGUARD DVRs (order of magnitude 10,000s — estimate) — No authoritative exposed-device count is published; the estimate is based on the large legacy installed base of 2016-era consumer/SMB DVRs that remain deployed and commonly port-forwarded, combined with Netlab's internet-wide scanning that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.

Weakness
CWE-1188
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.