{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/digital-watchdog/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VMAX A1 G4 DVRs (all)","VMAX IP G4 NVRs (all)","VMAX A1 PLUS (all)","VA1G4 Recorder (all)","VG4 Recorder (all)"],"_cs_severities":["critical"],"_cs_tags":["critical-infrastructure","ics","authentication-bypass","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["Digital Watchdog"],"content_html":"\u003cp\u003eMultiple critical vulnerabilities (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) have been identified in the Digital Watchdog VMAX DVR and NVR product lines. These vulnerabilities, primarily involving missing authentication (CWE-306) and the use of hard-coded credentials (CWE-798), allow unauthenticated remote attackers to gain full administrative or root-level control of affected devices. The vulnerabilities stem from predictable PRNG seeds, hard-coded FTP credentials that provide root-level file access, and missing authentication on critical functions that allow command execution. These products are widely deployed in commercial, government, healthcare, and transportation sectors. Exploitation allows an attacker to access surveillance footage, modify device configurations, or pivot into the internal network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative control over the DVR or NVR device. The impact includes unauthorized access to live and recorded surveillance video, manipulation of security configurations, and the ability to use the compromised hardware as a jump box or pivot point to conduct further lateral movement within the target's internal network. Given the typical deployment of these devices in critical infrastructure, this presents a significant risk to organizational confidentiality and network integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the immediate application of updated firmware provided by Digital Watchdog for all VMAX A1 G4, VMAX IP G4, VMAX A1 PLUS, VA1G4, and VG4 recorder models available at \u003ca href=\"https://digital-watchdog.com/downloads/\"\u003ehttps://digital-watchdog.com/downloads/\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRestrict access to management interfaces (Web UI and FTP services) to authorized, trusted IP addresses using internal network firewalls or ACLs.\u003c/li\u003e\n\u003cli\u003eMonitor internal network traffic for unauthorized FTP and HTTP administrative access originating from DVR/NVR devices.\u003c/li\u003e\n\u003cli\u003eIsolate these video surveillance devices on a dedicated, non-routable management VLAN to minimize the potential for lateral movement.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T16:31:12Z","date_published":"2026-09-15T16:31:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-digital-watchdog-vmax-vulnerabilities/","summary":"Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.","title":"Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products","url":"https://feed.craftedsignal.io/briefs/2026-09-digital-watchdog-vmax-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Digital Watchdog","version":"https://jsonfeed.org/version/1.1"}