Digital Watchdog VMAX DVR/NVR Multiple Vulnerabilities (Authentication Bypass, Hard-coded Credentials, Missing Authorization, Predictable Session Tokens)
First seen Sep 16, 2026 · Updated Sep 16, 2026 · CVSS 9.6
CISA has disclosed six vulnerabilities in Digital Watchdog VMAX DVR and NVR product lines, including hard-coded credentials, missing authentication, missing authorization, and predictable session tokens. Successful exploitation could grant an attacker full administrative control of the device, exposing live and recorded surveillance footage, allowing configuration changes, and enabling use of the device as a network pivot point.
Technical Analysis
The advisory details six CVEs affecting all versions of Digital Watchdog VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4 Recorder, and VG4 Recorder. CVE-2026-68953 (CWE-306) allows unauthenticated attackers to retrieve admin credentials in plaintext via crafted HTTP(S) requests; CVE-2026-66890 and CVE-2026-68950 (CWE-798, CVSS 9.6/8.8) involve hard-coded FTP/root credentials enabling remote root-level file access; CVE-2026-68070 (CWE-306, CVSS 8.8) permits unauthenticated command injection via raw bytes passed to a system command running as root; CVE-2026-66887 (CWE-862, CVSS 9.6) lacks authorization checks on state-changing CGI endpoints; and CVE-2026-66372 (CWE-337, CVSS 6.8) uses a predictable PRNG seed for session tokens, allowing session hijacking. Chained, these flaws allow adjacent-network attackers to gain root/admin control, view or exfiltrate surveillance footage, and pivot laterally into connected networks. These devices are typically deployed on physical security networks in commercial, healthcare, government, and transportation facilities; while not directly tied to AI agent frameworks, any organization using AI-driven video analytics, agentic monitoring/RAG pipelines ingesting camera feeds, or automation tooling with network access to these DVR/NVR systems could have credentials or footage exposed and risk the compromised device being used as a pivot point into agent-connected infrastructure.
Affected Systems
Digital Watchdog VMAX A1 G4 DVRs (all versions), VMAX IP G4 NVRs (all versions), VMAX A1 PLUS (all versions), VA1G4 Recorder (all versions), VG4 Recorder (all versions) — firmware prior to vendor-issued patches.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published; advisory notes no known public exploitation at this time. Indicators would include unauthorized HTTP(S) requests to device management interfaces, anomalous FTP logins with default/hard-coded credentials, and unexpected session tokens/predictable session IDs on device web interfaces.
Remediation Steps
- 1
Apply Vendor Firmware Update
Download and install the latest firmware from https://digital-watchdog.com/downloads/ for all affected VMAX DVR/NVR models to remediate hard-coded credentials, authentication bypass, and PRNG issues.
- 2
Isolate Devices from the Internet
Ensure DVR/NVR devices are not directly accessible from the Internet; place them behind firewalls and segment them from business/IT networks.
- 3
Restrict and Secure Remote Access
If remote access is required, use a well-maintained VPN rather than exposing device management interfaces directly; keep VPN software patched.
- 4
Disable/Restrict FTP Services
Disable FTP service where not required, or restrict access to trusted management networks only to mitigate hard-coded credential exploitation (CVE-2026-66890, CVE-2026-68950).
- 5
Monitor and Rotate Credentials
Rotate any credentials potentially exposed via CVE-2026-68953 and monitor for unauthorized access attempts to device APIs and FTP services.
- 6
Network Segmentation for Agent/Automation Systems
If AI-driven monitoring, analytics, or agent-based automation systems interface with these surveillance devices, segment and restrict their network access to prevent lateral pivoting from a compromised DVR/NVR.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.