Description
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Root Access
Action: Immediate Patch
AI Analysis

Impact

Hard‑coded credentials are embedded in the firmware of several Digital Watchdog devices. An attacker who can reach the device’s FTP service may start the ftpd daemon as root, thereby obtaining unrestricted file‑system access on the device and enabling full remote control. The vulnerability is classified as CWE‑798 and carries a CVSS score of 8.7, indicating a significant potential impact if exploited.

Affected Systems

The product families affected include Digital Watchdog VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware or model versions are listed in the advisory, so all currently deployed builds of these devices are potentially vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, suggesting a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. However, the attack vector requires only connectivity to the device’s FTP port, which is often exposed on internal or external networks. If accessed, the flaw provides full root access without further privilege escalation steps.

Generated by OpenCVE AI on September 18, 2026 at 13:58 UTC.

Remediation

Vendor Solution

Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:  https://digital-watchdog.com/downloads/


OpenCVE Recommended Actions

  • Download and install the updated firmware for the affected model from Digital Watchdog’s web site.
  • Disable or restrict the FTP service on the device while applying the firmware update.
  • If a firmware update is not yet available, block the FTP port (typically port 21) with firewall rules and monitor for unauthorized connection attempts.
  • Consider implementing network segmentation or internal network isolation to limit access to the FTP service when possible.

Generated by OpenCVE AI on September 18, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr
Vendors & Products Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
Title Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Digital Watchdog Va1g4 Recorder Vg4 Recorder Vmax A1 G4 Dvr Vmax A1 Plus Vmax Ip G4 Nvr
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T17:55:44.680Z

Reserved: 2026-08-03T21:27:04.643Z

Link: CVE-2026-68950

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:40.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:42.580

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-68950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:00:10Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials