Description
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR.

The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0).

The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions


The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.
Published: 2026-09-09
Score: 10 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

Certain KGUARD DVR devices expose a command execution service on all network interfaces without authentication. A remote attacker with network access can run arbitrary system commands, leading to full compromise of the device. The flaw stems from improper input validation and processing (CWE‑1188).

Affected Systems

Affected devices include KGUARD firmware appliances such as D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants. Firmware dated from 2016 is vulnerable; versions released after 2017 mitigate the issue by limiting the service to localhost.

Risk and Exploitability

The vulnerability carries a CVSS score of 10. It has been actively exploited by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware distribution and DDoS attacks. The EPSS score is 1%, indicating a low but nonzero probability of exploitation, and the lack of a KEV listing does not reduce the observed exploitation. Any network host with access to the exposed service can execute arbitrary commands, giving the attacker complete control over the DVR.

Generated by OpenCVE AI on September 10, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DVR firmware to a version released after 2017 that restricts the command execution service to localhost.
  • Apply a network firewall rule to block external connections to the vulnerable service interface, allowing only local host traffic.
  • Continuously monitor device logs for suspicious command execution activity and consider disabling the service if it is unnecessary.

Generated by OpenCVE AI on September 10, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Kguard
Kguard kguard Firmware
Vendors & Products Kguard
Kguard kguard Firmware

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.
Title KGUARD DVR unauthenticated remote command execution vulnerability
Weaknesses CWE-1188
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Kguard Kguard Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-09T12:28:04.444Z

Reserved: 2026-09-09T10:41:51.238Z

Link: CVE-2026-87827

cve-icon Vulnrichment

Updated: 2026-09-09T12:27:55.799Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T11:17:16.423

Modified: 2026-09-09T15:37:49.157

Link: CVE-2026-87827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:01:49Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default