news.mlab.sh
Back to the feed
vulnerability

Digital Watchdog VMAX DVR and NVR Product Lineups

Critical
Summary

Digital Watchdog has released firmware updates to address critical vulnerabilities in its VMAX DVR and NVR product lines. These vulnerabilities, including authentication bypasses and hard-coded credentials, could allow attackers to gain full administrative control of the devices, view surveillance footage, alter configurations, and potentially use the devices as network pivots. The CISA advises minimizing network exposure and using secure remote access methods like VPNs to mitigate the risk of exploitation.

Digital Watchdog has released firmware updates to address critical vulnerabilities in its VMAX DVR and NVR product lines. The affected products include Digital Watchdog VMAX A1 G4 DVRs, Digital Watchdog VMAX IP G4 NVRs, Digital Watchdog VMAX A1 PLUS, Digital Watchdog VA1G4 Recorder, and Digital Watchdog VG4 Recorder. These vulnerabilities allow unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. The vulnerabilities include an authentication bypass, use of hard-coded credentials, and missing authorization on state-changing CGIs. The CISA recommends users take defensive measures to minimize the risk of exploitation, including minimizing network exposure, isolating control systems networks, and using secure remote access methods like VPNs. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.

Read the full article at CISA Advisories