Digital Watchdog VMAX DVRs get six-CVE advisory
CISA details six vulnerabilities in Digital Watchdog VMAX DVR/NVR lineups that together enable full admin takeover; firmware updates are available.
CISA published an ICS advisory covering six vulnerabilities affecting Digital Watchdog's VMAX A1 G4, VMAX IP G4, VMAX A1 PLUS, VA1G4 and VG4 DVR/NVR product lines. The flaws include an authentication bypass that discloses plaintext admin credentials via crafted HTTP(S) requests (CVE-2026-68953), hard-coded credentials enabling remote root file access via FTP (CVE-2026-66890, CVE-2026-68950), missing authentication allowing arbitrary command execution as root (CVE-2026-68070), missing authorization on state-changing CGI functions (CVE-2026-66887), and predictable session tokens due to a weak PRNG seed (CVE-2026-66372). Chained, these issues could grant an attacker full administrative control of affected devices — viewing live/recorded surveillance footage, altering configurations, or using the device as a pivot point into the broader network.
Affected sectors include commercial facilities, government services, healthcare/public health, and transportation systems, with worldwide deployment. Digital Watchdog has released updated firmware for all affected models, available via the vendor's download portal. CISA states no known public exploitation has been reported and notes these vulnerabilities are not remotely exploitable, though the credential-disclosure and CGI issues are reachable over the network where the device's HTTP/FTP services are exposed. Defenders should prioritize firmware updates, ensure these devices are not internet-facing, and place them behind firewalls/VPNs per standard ICS network segmentation guidance. The vulnerabilities were responsibly reported to CISA by Scot Berner of TrustedSec.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free