Impact
The vulnerability stems from hard‑coded root credentials embedded in the firmware of certain Digital Watchdog devices. Because these credentials are always present and do not require user interaction to discover, an attacker who can reach the device's FTP interface can authenticate as root. This grants full access to the filesystem and the ability to read, modify, add, or delete any file, including configuration files and stored media, and could potentially allow execution of arbitrary code under root privileges.
Affected Systems
Affected models include Digital Watchdog VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware version ranges are listed, so all current iterations of these products are considered vulnerable until the updated firmware is applied.
Risk and Exploitability
The CVSS score of 9.4 reflects the very high severity of this flaw, and although the EPSS score is below 1%, the simplicity of the attack (network connection to FTP) means the potential for exploitation remains significant in environments where the devices are exposed to untrusted networks. The vulnerability is not presently listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet, but the presence of hard‑coded credentials and remote access ability make the risk high if the device is reachable over the network.
OpenCVE Enrichment