Critical Vulnerabilities in Digital Watchdog VMAX DVRs and NVRs Allow Full Administrative Control
CISA has issued an advisory detailing multiple critical vulnerabilities in Digital Watchdog's VMAX DVR and NVR product lines, which could allow attackers to gain full administrative control.

CISA has alerted users to a series of critical vulnerabilities affecting Digital Watchdog's VMAX Digital Video Recorder (DVR) and Network Video Recorder (NVR) product lineups. These security flaws, if successfully exploited, could grant attackers full administrative control over the affected devices, enabling them to view surveillance footage, alter configurations, and use the compromised devices as pivot points into internal networks.
The vulnerabilities span several product families, including VMAX A1 G4 DVRs, VMAX IP G4 NVRs, VMAX A1 PLUS, VA1G4 Recorder, and VG4 Recorder, all with versions listed as affected. The identified weaknesses include missing authentication for critical functions, the use of hard-coded credentials, missing authorization checks, and predictable seeds in the pseudo-random number generator (PRNG). These issues collectively pose a significant risk to organizations relying on these surveillance systems.
One of the most severe vulnerabilities, CVE-2026-66890, involves the use of hard-coded credentials. This flaw could allow remote attackers to gain root privileges and access files if the FTP service is reachable. Another critical vulnerability, CVE-2026-68070, involves missing authentication for a critical function, potentially allowing an attacker to execute commands as root by passing received bytes directly to a system command. The CVSS v3.1 score for this vulnerability is a high 8.8.
Further compounding the risk, CVE-2026-68953 allows unauthenticated remote attackers to bypass authentication and disclose sensitive device information, including administrator credentials in plaintext, by sending specially crafted HTTP(S) requests. This authentication bypass vulnerability has a CVSS v3.1 score of 6.5.
Other identified vulnerabilities include CVE-2026-66887, which involves missing authorization on state-changing CGIs and a lack of session checks, and CVE-2026-66890 and CVE-2026-68950, both related to hard-coded credentials that could allow remote root file access via FTP.
These devices are deployed worldwide across critical infrastructure sectors such as commercial facilities, government services, healthcare, and transportation systems. The potential for attackers to gain control of surveillance systems in these environments is a serious concern, as it could be used for espionage, disruption, or as a stepping stone for further network compromise.
Digital Watchdog has released updated firmware to address these vulnerabilities. CISA strongly advises users of the affected Digital Watchdog VMAX DVR and NVR products to download and install the latest firmware from the vendor's official website. Organizations should prioritize this update to mitigate the risk of exploitation and secure their surveillance infrastructure.