Description
The affected products are missing authorization on state-changing CGIs and session checks are not performed.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Configuration Change
Action: Immediate Patch
AI Analysis

Impact

The vulnerability manifests as missing authorization on state‑changing CGI endpoints and the absence of session checks, allowing an attacker to send crafted requests that modify device configuration. Failure to enforce authorization means any user who can reach the device can change settings, trigger actions, or disable security features, creating opportunities for denial of service, data tampering, or further exploitation. This flaw is classified as CWE-862, reflecting the lack of privilege enforcement.

Affected Systems

Digital Watchdog devices are affected, including the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR lineups. No specific firmware versions are listed, but all models in these product families are vulnerable. Updated firmware that resolves the authorization issue has been released and can be obtained from the vendor’s download portal.

Risk and Exploitability

The CVSS score of 9.4 marks the flaw as critical, indicating that remote attackers can achieve high‑impact actions. The EPSS score of less than 1% suggests a low but nonzero likelihood of exploitation in the wild, and the vulnerability is not currently in the CISA KEV catalog. The attack vector is inferred to be remote over the network, as the flaw involves unauthenticated HTTP requests to CGI exploited from any network segment that can reach the device’s management interface.

Generated by OpenCVE AI on September 18, 2026 at 13:58 UTC.

Remediation

Vendor Solution

Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:  https://digital-watchdog.com/downloads/


OpenCVE Recommended Actions

  • Download and install the latest firmware for the specific device model from Digital Watchdog at https://digital-watchdog.com/downloads/.
  • After the firmware update, verify that unauthenticated state‑changing CGI endpoints are disabled and that session checks are enforced.
  • Restrict network access to the device by configuring networks and disabling any unused management services to reduce exposure.

Generated by OpenCVE AI on September 18, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr
Vendors & Products Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description The affected products are missing authorization on state-changing CGIs and session checks are not performed.
Title Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Digital Watchdog Va1g4 Recorder Vg4 Recorder Vmax A1 G4 Dvr Vmax A1 Plus Vmax Ip G4 Nvr
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T17:57:45.143Z

Reserved: 2026-08-03T21:27:04.605Z

Link: CVE-2026-66887

cve-icon Vulnrichment

Updated: 2026-09-16T17:57:40.862Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:41.930

Modified: 2026-09-18T19:39:09.490

Link: CVE-2026-66887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses