Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4.

Upgrade to version 3.5.4.
Published: 2026-09-22
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the firmware’s handling of the X-Forwarded-For header; an unauthenticated remote client can supply a spoofed loopback address. This allows the attacker to bypass local-connection-only security controls on non‑TLS web interfaces and retrieve configuration details. The flaw is an authorization bypass through a user‑controlled key (CWE‑290).

Affected Systems

OpenEye Apex Network Video Recorder (NVR) firmware versions up to and including 3.2.9.376 are affected. Versions 3.5.4 and later contain the fix.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability represents moderate risk. No EPSS value is available, but the lack of a listed KEV entry suggests no widespread public exploitation yet. Exploitation requires only sending a crafted HTTP request with an X-Forwarded-For header containing a loopback address, and it can occur remotely over the unencrypted web interface.

Generated by OpenCVE AI on September 23, 2026 at 00:23 UTC.

Remediation

Vendor Solution

Upgrade to version 3.5.4.


OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading the firmware to version 3.5.4.
  • If upgrading is not immediately possible, block or strip X‑Forwarded‑For headers at any front‑end proxy or firewall, ensuring only trusted internal devices can reach the NVR’s non‑TLS web interface.
  • Disable or restrict access to the non‑TLS web interfaces entirely, enforcing TLS‑only connections for remote management.

Generated by OpenCVE AI on September 23, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Bypass of Local-Connection-Only Controls via Spoofed X-Forwarded-For Header

Tue, 22 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Securifera

Published:

Updated: 2026-09-22T23:19:15.124Z

Reserved: 2026-09-17T12:03:24.121Z

Link: CVE-2026-92929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T00:17:00.897

Modified: 2026-09-23T00:17:00.897

Link: CVE-2026-92929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T00:30:18Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing