Description
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Predictable web session tokens
Action: Apply Firmware Update
AI Analysis

Impact

The vulnerability stems from an insufficiently random pseudo‑random number generator because the device uses a predictable seed for the PRNG. The resulting web session tokens have limited entropy, which makes them predictable. An attacker who can observe or guess the seed can generate a valid session token and hijack the device’s administrative web interface, compromising both confidentiality and integrity.

Affected Systems

Digital Watchdog products impacted are the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. All listed models are supposedly affected; the advisory does not specify exact firmware revisions, so any firmware version before the issued update is considered vulnerable.

Risk and Exploitability

CVE‑2026‑66372 has a CVSS base score of 7.6, indicating a high‑severity flaw. The EPSS score is below 1 %, implying that exploitation activity is currently low or not observed, and it is not included in the CISA KEV catalog. The likely attack vector is a compromised or observed seed; based on the description, it is inferred that an attacker who can access or observe the device’s web traffic can exploit the predictable tokens, resulting in unauthorized web‑interface access.

Generated by OpenCVE AI on September 18, 2026 at 14:57 UTC.

Remediation

Vendor Solution

Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:  https://digital-watchdog.com/downloads/


OpenCVE Recommended Actions

  • Download and install the latest firmware for your Digital Watchdog model from the official download page and follow the vendor’s installation instructions.
  • Restrict access to the device’s web management interface to trusted networks or isolate it behind a firewall or VLAN; consider disabling web access from the public internet.
  • Disable or limit remote web management, or restrict it to access through a VPN or other secure channel to prevent unauthorized session hijacking.

Generated by OpenCVE AI on September 18, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr
Vendors & Products Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
Title Predictable Seed in Pseudo-Random Number Generator (PRNG) in Digital Watchdog VMAX DVR and NVR Product Lineups
Weaknesses CWE-337
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digital Watchdog Va1g4 Recorder Vg4 Recorder Vmax A1 G4 Dvr Vmax A1 Plus Vmax Ip G4 Nvr
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-17T18:46:41.717Z

Reserved: 2026-08-03T21:27:04.641Z

Link: CVE-2026-66372

cve-icon Vulnrichment

Updated: 2026-09-17T18:46:37.435Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:41.743

Modified: 2026-09-18T19:39:09.490

Link: CVE-2026-66372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:00:10Z

Weaknesses
  • CWE-337

    Predictable Seed in Pseudo-Random Number Generator (PRNG)