VYPR

Apex Network Video Recorder

by OpenEye

CVEs (4)

  • CVE-2026-94367HigSep 23, 2026
    risk 0.47cvss 7.2epss 0.01

    OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the…

  • CVE-2026-92928MedSep 23, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset…

  • CVE-2026-92930MedSep 23, 2026
    risk 0.40cvss 6.2epss 0.00

    OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset…

  • CVE-2026-92929MedSep 23, 2026
    risk 0.34cvss 5.3epss 0.00

    OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security…