Vulnerabilities · 16h ago
CISA issued a six-CVE advisory for Digital Watchdog's VMAX DVR and NVR product lines, and every listed version is affected. The advisory covers VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4 Recorders, and VG4 Recorders.
One flaw lets an unauthenticated attacker send crafted HTTP(S) requests and pull sensitive device data, including administrator credentials in plaintext. Another uses hard-coded credentials, so if FTP is reachable an attacker can log in with built-in secrets and reach files with root privileges; CISA says successful abuse can expose live and recorded video, change settings, and turn the recorder into a network pivot point.
CISA says updated firmware is available. The broad vers: all/* listing suggests many deployments may be affected at once, and surveillance gear that sits on the network can become more than a camera box if an attacker gets in.
CVEs in this update
6 CVEs
Across VMAX A1 G4 DVR, VMAX IP G4 NVR, VMAX A1 PLUS, and related packages.
2 critical · 2 high · 2 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-66890 · 9.6 CRITICAL
1 source covering this story
Digital Watchdog VMAX DVR and NVR Product Lineups | CISA
Digital Watchdog VMAX DVR and NVR Product Lineups Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a…
Part of the PlainSec briefing for 2026-09-16