Digital Watchdog
Products
4- 6 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68950 | Hig | 0.57 | 8.8 | 0.00 | Sep 15, 2026 | The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. | ||
| CVE-2022-34540 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request. | ||
| CVE-2022-34539 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request. | ||
| CVE-2022-34538 | Hig | 0.57 | 8.8 | 0.03 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request. | ||
| CVE-2022-34536 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token. | ||
| CVE-2022-34535 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files. | ||
| CVE-2022-34534 | Hig | 0.49 | 7.5 | 0.03 | Jul 19, 2022 | Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call. | ||
| CVE-2026-68953 | Med | 0.42 | 6.5 | 0.01 | Sep 15, 2026 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. | ||
| CVE-2022-34537 | Med | 0.35 | 5.4 | 0.00 | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi. |
- risk 0.57cvss 8.8epss 0.00
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
- risk 0.57cvss 8.8epss 0.01
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.
- risk 0.57cvss 8.8epss 0.01
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.
- risk 0.57cvss 8.8epss 0.03
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.
- risk 0.49cvss 7.5epss 0.01
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
- risk 0.49cvss 7.5epss 0.01
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
- risk 0.49cvss 7.5epss 0.03
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
- risk 0.42cvss 6.5epss 0.01
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
- risk 0.35cvss 5.4epss 0.00
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.