Impact
The vulnerability lies in the firmware’s handling of the X-Forwarded-For header; an unauthenticated remote client can supply a spoofed loopback address. This allows the attacker to bypass local-connection-only security controls on non‑TLS web interfaces and retrieve configuration details. The flaw is an authorization bypass through a user‑controlled key (CWE‑290).
Affected Systems
OpenEye Apex Network Video Recorder (NVR) firmware versions up to and including 3.2.9.376 are affected. Versions 3.5.4 and later contain the fix.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability represents moderate risk. No EPSS value is available, but the lack of a listed KEV entry suggests no widespread public exploitation yet. Exploitation requires only sending a crafted HTTP request with an X-Forwarded-For header containing a loopback address, and it can occur remotely over the unencrypted web interface.
OpenCVE Enrichment