Vulnerabilities · 16h ago

CISA Flags Digital Watchdog Recorders for Full Control

CISA issued a six-CVE advisory for Digital Watchdog's VMAX DVR and NVR product lines, and every listed version is affected. The advisory covers VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4 Recorders, and VG4 Recorders.

One flaw lets an unauthenticated attacker send crafted HTTP(S) requests and pull sensitive device data, including administrator credentials in plaintext. Another uses hard-coded credentials, so if FTP is reachable an attacker can log in with built-in secrets and reach files with root privileges; CISA says successful abuse can expose live and recorded video, change settings, and turn the recorder into a network pivot point.

CISA says updated firmware is available. The broad vers: all/* listing suggests many deployments may be affected at once, and surveillance gear that sits on the network can become more than a camera box if an attacker gets in.

CVEs in this update

6 CVEs

Across VMAX A1 G4 DVR, VMAX IP G4 NVR, VMAX A1 PLUS, and related packages.

2 critical · 2 high · 2 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-66890 · 9.6 CRITICAL

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-16

Editions

Related stories