Digital Watchdog VMAX DVR and NVR Product Lineups
Digital Watchdog VMAX DVR/NVR devices vulnerable to critical security flaws.
Summary
Multiple critical vulnerabilities have been discovered in Digital Watchdog's VMAX DVR and NVR product lines. These flaws, including missing authentication, hard-coded credentials, and missing authorization, could allow attackers to gain full administrative control, view surveillance footage, and use the devices as network pivot points. Digital Watchdog has released updated firmware to address these issues.
Full text
ICS Advisory Digital Watchdog VMAX DVR and NVR Product Lineups Release DateSeptember 15, 2026 Alert CodeICSA-26-258-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) CVSS Vendor Equipment Vulnerabilities v3 9.6 Digital Watchdog Digital Watchdog VMAX DVR and NVR Product Lineups Missing Authentication for Critical Function, Use of Hard-coded Credentials, Missing Authorization, Predictable Seed in Pseudo-Random Number Generator (PRNG) Background Critical Infrastructure Sectors: Commercial Facilities, Government Services and Facilities, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-68953 The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-66890 The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-68070 The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-68950 The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-66887 The affected products are missing authorization on state-changing CGIs and session checks are not performed. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.6 CRITICAL CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-66372 The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space. View CVE Details Affected Products Digital Watchdog VMAX DVR and NVR Product Lineups Vendor:Digital Watchdog Product Version:Digital Watchdog VMAX A1 G4 DVRs: vers:all/*, Digital Watchdog VMAX IP G4 NVRs: vers:all/*, Digital Watchdog VMAX A1 PLUS: vers:all/*, Digital Watchdog VA1G4 Recorder: vers:all/*, Digital Watchdog VG4 Recorder: vers:all/* Product Status:known_affected Remediations MitigationDigital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at: https://digital-watchdog.com/downloads/ Relevant CWE: CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG) Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 7.6 HIGH CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Scot Berner of TrustedSec reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject
Indicators of Compromise
- cve — CVE-2026-68953
- cve — CVE-2026-66890
- cve — CVE-2026-68070
- cve — CVE-2026-68950
- cve — CVE-2026-66887
- cve — CVE-2026-66372