Impact
The vulnerability stems from an insufficiently random pseudo‑random number generator because the device uses a predictable seed for the PRNG. The resulting web session tokens have limited entropy, which makes them predictable. An attacker who can observe or guess the seed can generate a valid session token and hijack the device’s administrative web interface, compromising both confidentiality and integrity.
Affected Systems
Digital Watchdog products impacted are the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. All listed models are supposedly affected; the advisory does not specify exact firmware revisions, so any firmware version before the issued update is considered vulnerable.
Risk and Exploitability
CVE‑2026‑66372 has a CVSS base score of 7.6, indicating a high‑severity flaw. The EPSS score is below 1 %, implying that exploitation activity is currently low or not observed, and it is not included in the CISA KEV catalog. The likely attack vector is a compromised or observed seed; based on the description, it is inferred that an attacker who can access or observe the device’s web traffic can exploit the predictable tokens, resulting in unauthorized web‑interface access.
OpenCVE Enrichment