Machine-generated analysis · WAYSCloud LLM
All firmware versions of Digital Watchdog VMAX DVR and NVR models are listed as vulnerable. The vulnerabilities could give an unauthenticated attacker full administrative control.
Context
The advisory concerns Digital Watchdog VMAX DVR and NVR product lineups, including the VMAX A1 G4 DVR, VMAX IP G4 NVR, VMAX A1 PLUS, VA1G4 Recorder, and VG4 Recorder. It states that authentication bypass, hard-coded credentials, missing authorization, and a predictable PRNG allow remote attackers to view live and recorded video, alter configurations, and use the device as a network pivot point. The advisory notes deployments across commercial facilities, government services, healthcare, and transportation sectors worldwide.
Operator considerations
Check: inventory all Digital Watchdog VMAX DVR and NVR devices and verify model and firmware version.
Isolate: segment these devices on a dedicated VLAN or restrict inbound network access.
Log: monitor HTTP(S) traffic to the devices for crafted requests or unauthorized authentication attempts.
Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.
The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected:
VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372)
VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-6807...
Read the full advisory on CISA →