Executive Summary
In September 2026, CISA disclosed six critical vulnerabilities in Digital Watchdog VMAX DVR and NVR surveillance systems affecting all product versions worldwide. The vulnerabilities include authentication bypass (CVE-2026-68953), hard-coded credentials (CVE-2026-66890, CVE-2026-68950), missing authentication for critical functions (CVE-2026-68070), missing authorization (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, allowing attackers to view surveillance footage, alter configurations, and use devices as network pivot points with root-level access.
This disclosure highlights the growing security risks in IoT surveillance infrastructure, particularly as organizations increasingly deploy connected security devices without proper hardening. The vulnerabilities demonstrate classic IoT security failures that enable lateral movement within critical infrastructure networks.
Why This Matters Now
These vulnerabilities expose fundamental security gaps in widely-deployed surveillance infrastructure used across critical sectors including healthcare, transportation, and government facilities, creating urgent risks for lateral movement and surveillance compromise.
Attack Path Analysis
Attackers exploit multiple critical vulnerabilities in Digital Watchdog VMAX DVR/NVR systems to gain initial network access through authentication bypass and hardcoded credentials. They escalate privileges using missing authentication controls to execute system commands as root, then move laterally through the surveillance network infrastructure using the compromised devices as pivot points. Command and control is established through FTP services and web interfaces, enabling exfiltration of surveillance footage, device configurations, and network credentials. The attack culminates in complete compromise of the surveillance infrastructure, potentially disrupting critical monitoring capabilities across commercial facilities, healthcare, and transportation systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploit CVE-2026-68953 authentication bypass vulnerability by sending crafted HTTP requests to expose administrator credentials in plaintext, combined with CVE-2026-66890 hardcoded credentials for direct device access
Related CVEs
CVE-2026-68953
CVSS 6.5Authentication bypass vulnerability in Digital Watchdog VMAX DVR/NVR products allows unauthenticated remote attackers to disclose sensitive device information including administrator credentials in plaintext via crafted HTTP(S) requests.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploitCVE-2026-66890
CVSS 9.6Use of hard-coded credentials in Digital Watchdog VMAX products allows remote access to files with root privileges where FTP is reachable.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploitCVE-2026-68070
CVSS 8.8Missing authentication for critical function vulnerability allows attackers to run as root and pass received bytes directly to system commands.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploitCVE-2026-68950
CVSS 8.8Hard-coded credentials vulnerability allows attackers to run the ftpd service as root, providing remote root file access where FTP is reachable.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploitCVE-2026-66887
CVSS 9.6Missing authorization vulnerability on state-changing CGIs with no session checks performed, allowing unauthorized configuration changes.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploitCVE-2026-66372
CVSS 6.8Predictable pseudo-random number generator vulnerability allows web session tokens to be predictable, bounding token entropy to the seed space.
Affected Products:
Digital Watchdog VMAX A1 G4 DVR – all versions
Digital Watchdog VMAX IP G4 NVR – all versions
Digital Watchdog VMAX A1 PLUS – all versions
Digital Watchdog VA1G4 Recorder – all versions
Digital Watchdog VG4 Recorder – all versions
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts: Local Accounts
Unsecured Credentials: Credentials In Files
Remote Services: Distributed Component Object Model
Command and Scripting Interpreter: Unix Shell
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Data from Local System
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration Standards for System Components
Control ID: 2.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
CISA ZTMM 2.0 – Identity and Access Management
Control ID: IA-2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Security/Investigations
Critical vulnerabilities in Digital Watchdog surveillance systems enable authentication bypass, hard-coded credentials exploitation, and complete administrative control compromise of security infrastructure.
Government Administration
Government facilities using affected DVR/NVR systems face exposure to unauthorized surveillance access, configuration manipulation, and potential use as network pivot points for lateral movement.
Health Care / Life Sciences
Healthcare surveillance systems vulnerable to authentication bypass and hard-coded credentials expose patient areas to unauthorized monitoring and HIPAA compliance violations through administrative control compromise.
Commercial Real Estate
Commercial facilities relying on Digital Watchdog surveillance face risks of unauthorized live/recorded video access and device compromise enabling attackers to monitor premises and operations.
Sources
- Digital Watchdog VMAX DVR and NVR Product Lineupshttps://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01Verified
- Digital Watchdog Security Updates and Downloadshttps://digital-watchdog.com/downloads/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain attacker movement through surveillance network infrastructure by enforcing segmentation boundaries and controlling east-west traffic flows. The compromised DVR/NVR devices would face reduced lateral reach and restricted communication paths to other network assets.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The compromised DVR/NVR devices would likely face restricted network visibility and limited access to adjacent surveillance infrastructure through enforced network boundaries and controlled traffic flows.
Control: Zero Trust Segmentation
Mitigation: Root-level access on compromised devices would likely be constrained to isolated network segments, reducing the scope of privileged operations and limiting exposure to connected surveillance systems.
Control: East-West Traffic Security
Mitigation: Lateral movement from compromised surveillance devices would likely be constrained by granular traffic inspection and policy enforcement, reducing attacker reach to other network infrastructure components.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face enhanced monitoring and policy enforcement, constraining unauthorized service interactions and reducing persistent access capabilities across distributed surveillance infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by controlled egress policies and traffic inspection, reducing the volume and scope of sensitive surveillance data that could be extracted from the network.
The overall impact to surveillance operations would likely be reduced in scope, with compromised devices constrained to isolated network segments and limited ability to disrupt broader security monitoring capabilities across the facility.
Impact at a Glance
Affected Business Functions
- Physical Security Surveillance
- Video Monitoring and Recording
- Incident Response Documentation
- Facilities Access Control
Estimated downtime: 7 days
Estimated loss: $150,000
Surveillance video footage, administrator credentials in plaintext, device configuration data, and potential access to networked systems through device compromise. Critical facilities monitoring capabilities could be compromised affecting security operations across commercial facilities, healthcare, government, and transportation sectors.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate IoT/ICS devices from corporate networks and prevent lateral movement to critical infrastructure
- • Deploy egress security controls to detect and block unauthorized data exfiltration from surveillance systems to external destinations
- • Enable multicloud visibility and anomaly detection to identify suspicious access patterns and repeated malformed requests against IoT devices
- • Establish encrypted traffic inspection capabilities to detect hardcoded credential abuse and unauthorized administrative access attempts
- • Implement inline IPS with IoT-specific signatures to block known exploit patterns targeting surveillance equipment vulnerabilities



