logo

Digital Watchdog VMAX DVR/NVR Missing Authorization Enables Takeover

ID: c2e267c1-388f-5de4-8356-186021406db8

STIX ID: report--c2e267c1-388f-5de4-8356-186021406db8

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-09-16

Date Updated: 2026-09-17

...
...

CISA ICSA-26-258-01 discloses CVE-2026-66887, a critical (CVSS v3.1 9.6) missing-authorization vulnerability in all versions of five Digital Watchdog VMAX DVR/NVR product lines that allows an attacker on the local network to issue state-changing CGI commands without authenticating, potentially yielding full administrative control, surveillance access, and network pivot; CISA grouped this with five related flaws, Digital Watchdog released firmware updates, and recommended isolation, access restrictions, and monitoring, with no known public exploitation as of September 15, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.