Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2868+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. Digital Watchdog VMAX DVR/NVR Missing Authorization Enables Takeover
Digital Watchdog VMAX DVR/NVR Missing Authorization Enables Takeover

Critical Security Alert

This vulnerability is actively being exploited. Immediate action is recommended.

SECURITYCRITICALCVE-2026-66887

Digital Watchdog VMAX DVR/NVR Missing Authorization Enables Takeover

CVE-2026-66887 (CVSS 9.6) lets attackers bypass session checks on Digital Watchdog VMAX DVR/NVR state-changing CGIs for full admin control.

Dylan H.

Security Team

September 16, 2026
3 min read

Affected Products

  • Digital Watchdog VMAX DVR/NVR — all versions (5 product lines)

Executive Summary

CISA has published ICS Advisory ICSA-26-258-01, disclosing a critical missing authorization vulnerability (CVE-2026-66887) affecting all versions of five Digital Watchdog VMAX DVR/NVR product lines. State-changing CGI endpoints on the devices fail to perform session checks, letting an attacker on the local network issue administrative commands without ever authenticating. The advisory groups this flaw alongside five related issues — including the hard-coded credentials bug tracked as CVE-2026-66890 — reported to CISA by Scot Berner of TrustedSec.

CVSS Score: 9.6 (Critical) — CVSS v3.1; 9.4 under CVSS v4.0


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-66887
CVSS v3.19.6 — AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.09.4
TypeMissing Authorization on State-Changing CGIs
Attack VectorAdjacent network (local network access to the device)
Privileges RequiredNone
AdvisoryCISA ICSA-26-258-01
Reported ByScot Berner, TrustedSec

Affected Products

VendorProduct LinesAffected Versions
Digital WatchdogVMAX DVR/NVR (five product lines)All versions

CISA's advisory covers six vulnerabilities total across these product lines, spanning authentication bypasses, hard-coded credentials, missing authorization, and predictable session-token generation. This entry addresses the missing-authorization issue specifically; see CVE-2026-66890 for the companion hard-coded FTP credentials flaw.


Technical Details

The affected VMAX DVR/NVR firmware exposes CGI endpoints used to change device state — configuration changes, user management, and other administrative actions — without verifying that the requester holds a valid, authenticated session. An attacker with network access to the device's management interface can therefore issue these state-changing requests directly, bypassing the authentication flow entirely.

Impact of Successful Exploitation

ImpactDescription
Full Administrative ControlAttacker gains equivalent access to a legitimate administrator
Surveillance AccessView live and recorded video feeds without credentials
Configuration TamperingAlter device settings, disable logging, add rogue accounts
Network PivotUse the compromised DVR/NVR as a foothold into the broader network

CISA reports no known public exploitation at the time of publication (September 15, 2026).


Remediation

Step 1: Apply the Firmware Update

Digital Watchdog has released updated firmware addressing this and the related vulnerabilities in the same advisory. Contact Digital Watchdog support or your integrator to obtain and apply the current firmware for your specific VMAX DVR/NVR model.

Step 2: Network Segmentation

  1. Place DVR/NVR management interfaces on an isolated VLAN, not reachable from general user networks or the internet.
  2. Restrict access to the device's web/CGI interface to a small set of trusted management hosts via firewall rules.
  3. Disable or restrict remote/cloud access features that aren't in active use.

Step 3: Monitor for Abuse

  • Review device logs (where available) for configuration changes or new accounts that weren't initiated by known administrators.
  • Watch network traffic for CGI requests to the device from unexpected source IPs.

References

  • CISA ICS Advisory ICSA-26-258-01
  • NIST NVD — CVE-2026-66887

Related Reading

  • Digital Watchdog VMAX Root FTP Credentials Baked In
  • Critical SSRF in GitLab MCP Server Leaks Private Tokens to Attackers
#ICS#OT#Digital Watchdog#DVR#NVR#CVE-2026-66887#CISA

Related Articles

Digital Watchdog VMAX Root FTP Credentials Baked In

CVE-2026-66890 (CVSS 9.6) hard-codes root-level FTP credentials into Digital Watchdog VMAX DVR/NVR firmware, enabling remote root file access.

4 min read

Shinobi NVR: Hardcoded Child-Node Key Enables Unauthenticated Database Compromise (CVE-2026-82448)

CVE-2026-82448 (CVSS 9.8): a hardcoded key in Shinobi's child-node service lets attackers run arbitrary SQL against user and camera data.

5 min read

CVE-2026-14365: TrueBooker WordPress Plugin Authorization Bypass Enables Unauthenticated Password Change

A second critical flaw in the TrueBooker Appointment Booking WordPress plugin allows unauthenticated attackers to change the password of any user, including administrators, due to missing authorization checks. CVSS 9.8.

5 min read
Back to all Security Alerts