#OT
All CosmicBytez Labs articles tagged #OT, across news, security advisories, how-to guides, and projects.
- Security
Digital Watchdog VMAX DVR/NVR Missing Authorization Enables Takeover
CVE-2026-66887 (CVSS 9.6) lets attackers bypass session checks on Digital Watchdog VMAX DVR/NVR state-changing CGIs for full admin control.
- Security
Digital Watchdog VMAX Root FTP Credentials Baked In
CVE-2026-66890 (CVSS 9.6) hard-codes root-level FTP credentials into Digital Watchdog VMAX DVR/NVR firmware, enabling remote root file access.
- Security
CVE-2026-61884: Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass (CVSS 9.8)
A critical authentication bypass in the Tycon Systems TPDIN-Monitor-WEB2 web interface allows unauthenticated remote attackers to gain full administrative...
- Security
OpENer CIP Integer Overflow — CVE-2026-51536
A critical integer truncation vulnerability in OpENer 2.3.0 allows network attackers to trigger heap corruption or denial of service by sending malformed...
- Security
OpENer Out-of-Bounds Read in CIP ForwardOpen — CVE-2026-51537
A critical out-of-bounds read vulnerability in OpENer 2.3.0 allows unauthenticated attackers to crash industrial EtherNet/IP devices by sending malformed...
- Security
OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538
A critical access control vulnerability in OpENer 2.3.0 allows unauthenticated attackers to send privileged encapsulation commands using arbitrary session...