Digital Watchdog VMAX Root FTP Credentials Baked In
ID: 045256a0-7198-561c-915b-a460537b14d0
STIX ID: report--045256a0-7198-561c-915b-a460537b14d0
Feed Name: CosmicBytez Labs
Threat Score
CISA advisory ICSA-26-258-01 discloses CVE-2026-66890: Digital Watchdog VMAX DVR/NVR devices ship with hard-coded, non-rotatable FTP credentials that provide remote root-equivalent filesystem access (CVSS v3.1 9.6). Digital Watchdog has released firmware updates; mitigations include applying the firmware, blocking or disabling FTP, network segmentation, and treating exposed devices as potentially compromised. CISA reported no known public exploitation as of September 15, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
