Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4.

Upgrade to version 3.5.4.
Published: 2026-09-22
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Password Reset Access
Action: Patch
AI Analysis

Impact

OpenEye Apex Network Video Recorder firmware contains a hardcoded, undocumented recovery account whose credentials cannot be changed or disabled. An unauthenticated remote attacker can authenticate to the password‑reset workflow using this account, allowing automatic password recovery, though it does not grant full administrator rights. The design existed since firmware 2.2.3.4.

Affected Systems

OpenEye Apex Network Video Recorder (NVR), firmware 3.2.9.376, and all earlier firmware versions including 2.2.3.4 that retain the same hardcoded account.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS is not available, suggesting no measured exploitation probability at this time. The vulnerability is not listed in CISA KEV. The likely attack vector is a remote, unauthenticated attacker using the public or remote network to reach the password‑reset endpoint. Because the account does not grant administrator privileges, gaining full control would require additional vulnerabilities, but the exposed credential still allows the attacker to reset passwords or potentially chain with other weaknesses.

Generated by OpenCVE AI on September 23, 2026 at 00:23 UTC.

Remediation

Vendor Solution

Upgrade to version 3.5.4.


OpenCVE Recommended Actions

  • Upgrade the firmware to version 3.5.4 to eliminate the hardcoded recovery account.
  • If possible after upgrading, permanently disable or remove the recovery account feature via device configuration settings.
  • Apply network segmentation or firewall rules to restrict management interface access to trusted networks only.

Generated by OpenCVE AI on September 23, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Recovery Account Allows Unauthenticated Password Reset in OpenEye Apex NVR

Tue, 22 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Securifera

Published:

Updated: 2026-09-22T23:19:14.211Z

Reserved: 2026-09-17T12:03:24.121Z

Link: CVE-2026-92928

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T00:16:59.773

Modified: 2026-09-23T00:16:59.773

Link: CVE-2026-92928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T00:30:18Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials