Medium severity6.5NVD Advisory· Published Sep 23, 2026
CVE-2026-92928
CVE-2026-92928
Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4.
Upgrade to version 3.5.4.
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.