Impact
OpenEye Apex Network Video Recorder firmware contains a hardcoded, undocumented recovery account whose credentials cannot be changed or disabled. An unauthenticated remote attacker can authenticate to the password‑reset workflow using this account, allowing automatic password recovery, though it does not grant full administrator rights. The design existed since firmware 2.2.3.4.
Affected Systems
OpenEye Apex Network Video Recorder (NVR), firmware 3.2.9.376, and all earlier firmware versions including 2.2.3.4 that retain the same hardcoded account.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS is not available, suggesting no measured exploitation probability at this time. The vulnerability is not listed in CISA KEV. The likely attack vector is a remote, unauthenticated attacker using the public or remote network to reach the password‑reset endpoint. Because the account does not grant administrator privileges, gaining full control would require additional vulnerabilities, but the exposed credential still allows the attacker to reset passwords or potentially chain with other weaknesses.
OpenCVE Enrichment