<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VMAX A1 G4 DVRs (All) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vmax-a1-g4-dvrs-all/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 16:31:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vmax-a1-g4-dvrs-all/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products</title><link>https://feed.craftedsignal.io/briefs/2026-09-digital-watchdog-vmax-vulnerabilities/</link><pubDate>Tue, 15 Sep 2026 16:31:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-digital-watchdog-vmax-vulnerabilities/</guid><description>Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.</description><content:encoded><![CDATA[<p>Multiple critical vulnerabilities (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) have been identified in the Digital Watchdog VMAX DVR and NVR product lines. These vulnerabilities, primarily involving missing authentication (CWE-306) and the use of hard-coded credentials (CWE-798), allow unauthenticated remote attackers to gain full administrative or root-level control of affected devices. The vulnerabilities stem from predictable PRNG seeds, hard-coded FTP credentials that provide root-level file access, and missing authentication on critical functions that allow command execution. These products are widely deployed in commercial, government, healthcare, and transportation sectors. Exploitation allows an attacker to access surveillance footage, modify device configurations, or pivot into the internal network.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants an attacker full administrative control over the DVR or NVR device. The impact includes unauthorized access to live and recorded surveillance video, manipulation of security configurations, and the ability to use the compromised hardware as a jump box or pivot point to conduct further lateral movement within the target's internal network. Given the typical deployment of these devices in critical infrastructure, this presents a significant risk to organizational confidentiality and network integrity.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize the immediate application of updated firmware provided by Digital Watchdog for all VMAX A1 G4, VMAX IP G4, VMAX A1 PLUS, VA1G4, and VG4 recorder models available at <a href="https://digital-watchdog.com/downloads/">https://digital-watchdog.com/downloads/</a>.</li>
<li>Restrict access to management interfaces (Web UI and FTP services) to authorized, trusted IP addresses using internal network firewalls or ACLs.</li>
<li>Monitor internal network traffic for unauthorized FTP and HTTP administrative access originating from DVR/NVR devices.</li>
<li>Isolate these video surveillance devices on a dedicated, non-routable management VLAN to minimize the potential for lateral movement.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>critical-infrastructure</category><category>ics</category><category>authentication-bypass</category><category>remote-code-execution</category></item></channel></rss>