Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products
Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.
Multiple critical vulnerabilities (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) have been identified in the Digital Watchdog VMAX DVR and NVR product lines. These vulnerabilities, primarily involving missing authentication (CWE-306) and the use of hard-coded credentials (CWE-798), allow unauthenticated remote attackers to gain full administrative or root-level control of affected devices. The vulnerabilities stem from predictable PRNG seeds, hard-coded FTP credentials that provide root-level file access, and missing authentication on critical functions that allow command execution. These products are widely deployed in commercial, government, healthcare, and transportation sectors. Exploitation allows an attacker to access surveillance footage, modify device configurations, or pivot into the internal network.
Impact
Successful exploitation grants an attacker full administrative control over the DVR or NVR device. The impact includes unauthorized access to live and recorded surveillance video, manipulation of security configurations, and the ability to use the compromised hardware as a jump box or pivot point to conduct further lateral movement within the target's internal network. Given the typical deployment of these devices in critical infrastructure, this presents a significant risk to organizational confidentiality and network integrity.
Recommendation
- Prioritize the immediate application of updated firmware provided by Digital Watchdog for all VMAX A1 G4, VMAX IP G4, VMAX A1 PLUS, VA1G4, and VG4 recorder models available at https://digital-watchdog.com/downloads/.
- Restrict access to management interfaces (Web UI and FTP services) to authorized, trusted IP addresses using internal network firewalls or ACLs.
- Monitor internal network traffic for unauthorized FTP and HTTP administrative access originating from DVR/NVR devices.
- Isolate these video surveillance devices on a dedicated, non-routable management VLAN to minimize the potential for lateral movement.
Immediate actions
Upgrade all Digital Watchdog VMAX firmware to the latest versions released after 2026-09-15
Mitigations
Restrict network access to device management ports and place devices in an isolated management VLAN
All listed CVEs