Description
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is an authentication bypass that allows an unauth or HTTPS requests to affected Digital Watchdog devices. Once the bypass succeeds, the device returns sensitive information, including administrator credentials stored in plaintext. This flaw results in the disclosure of device configuration details and access credentials, compromising the confidentiality of the device and any network it is connected to. This flaw is an instance of Missing Authentication (CWE-306).

Affected Systems

Digital Watchdog products affected include the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware or model versions are listed, so any running firmware on these models is considered vulnerable until patched.

Risk and Exploitability

The CVSS score of 7.1 indicates medium to high severity, while the EPSS score of less than 1% suggests that active exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been documented. The attack is inferred to be executed remotely over the device’s HTTP(S) interface, requiring no credentials to trigger the authentication bypass and enabling the attacker to read sensitive information immediately after the bypass is achieved.

Generated by OpenCVE AI on September 18, 2026 at 14:36 UTC.

Remediation

Vendor Solution

Digital Watchdog has released updated firmware for the affected products. Users should download and install the updated firmware for their model at:   https://digital-watchdog.com/downloads/


OpenCVE Recommended Actions

  • Download and install the latest firmware for your Digital Watchdog model from https://digital-watchdog.com/downloads/
  • Apply the firmware update to each affected device to remove the authentication bypass
  • Limit network exposure by restricting access to the web interface with firewall rules or VPN until the patch is applied

Generated by OpenCVE AI on September 18, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr
Vendors & Products Digital Watchdog
Digital Watchdog va1g4 Recorder
Digital Watchdog vg4 Recorder
Digital Watchdog vmax A1 G4 Dvr
Digital Watchdog vmax A1 Plus
Digital Watchdog vmax Ip G4 Nvr

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
Title Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digital Watchdog Va1g4 Recorder Vg4 Recorder Vmax A1 G4 Dvr Vmax A1 Plus Vmax Ip G4 Nvr
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T17:52:09.566Z

Reserved: 2026-08-03T21:27:04.638Z

Link: CVE-2026-68953

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:06.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:42.743

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-68953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:45:09Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function