Impact
Hard‑coded credentials are embedded in the firmware of several Digital Watchdog devices. An attacker who can reach the device’s FTP service may start the ftpd daemon as root, thereby obtaining unrestricted file‑system access on the device and enabling full remote control. The vulnerability is classified as CWE‑798 and carries a CVSS score of 8.7, indicating a significant potential impact if exploited.
Affected Systems
The product families affected include Digital Watchdog VA1G4 Recorder, VG4 Recorder, VMAX A1 G4 DVR, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware or model versions are listed in the advisory, so all currently deployed builds of these devices are potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, suggesting a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. However, the attack vector requires only connectivity to the device’s FTP port, which is often exposed on internal or external networks. If accessed, the flaw provides full root access without further privilege escalation steps.
OpenCVE Enrichment