Description
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a missing authentication check for a critical function that grants root-level access. The flaw allows an attacker to transmit arbitrary bytes to the device, which the firmware then passes directly to a system command without validation. This results in the ability to execute arbitrary code, compromising confidentiality, integrity, and availability of the device. The weakness corresponds to CWE-306, representing an authentication bypass.

Affected Systems

Affected vendors include Digital Watchdog. The impacted models are the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware or version range is listed, so any device running the referenced product lineups is considered potentially vulnerable until a patched firmware is applied.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not currently listed in the CISA KEV catalog, which may reflect limited known exploitation. The likely attack vector is remote network access to the device’s management interface, where the unauthenticated function can be invoked directly by an attacker in the local network or over the internet if exposed. Successful exploitation would grant full root control over the device.

Generated by OpenCVE AI on September 18, 2026 at 13:59 UTC.

Remediation

Vendor Solution

Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:  https://digital-watchdog.com/downloads/


OpenCVE Recommended Actions

  • Apply the updated firmware released by Digital Watchdog for the specific device model from the vendor’s download page.
  • If an immediate firmware update is not possible, restrict network access by blocking management ports or placing the device behind a firewall to prevent unauthenticated remote access.
  • Continuously monitor device logs for anomalous command execution attempts and implement intrusion detection to detect unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr
Vendors & Products Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
Title Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Digital Watchdog Va1g4 Recorder Vg4 Recorder Vmax A1 G4 Dvr Vmax A1 Plus Vmax Ip G4 Nvr
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T17:55:13.474Z

Reserved: 2026-08-03T21:27:04.634Z

Link: CVE-2026-68070

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:08.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:42.253

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-68070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function