Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4.

Upgrade to version 3.5.4.
Published: 2026-09-22
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Administrative Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

OpenEye Apex Network Video Recorder firmware implements an administrator password-reset unlock-code process that omits any per-device secret or server‑side cryptographic material. The design allows an attacker who can access the console and the privileged reset workflow to forge a valid unlock code offline. By submitting the forged code, the attacker can reset the system’s administrator password and gain full administrative control of the device. The flaw has existed since at least firmware 2.2.3.4 and persists in the affected 3.2.9.376 release. The underlying weakness is characterized as CWE‑330, improper use of randomness and lack of authentication.

Affected Systems

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 (and all earlier versions lacking the fix) are vulnerable. The vendor recommends upgrading to firmware 3.5.4 to remediate the flaw.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity, but physical access to the device is required for exploitation. Because the attacker can forge the unlock code without needing network credentials or remote access, the risk is confined to environments where an attacker can reach the console. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not widely exploited in the wild. Nonetheless, any scenario that allows an attacker to manipulate the password‑reset workflow grants them full administrative privileges and potential lateral movement within the network.

Generated by OpenCVE AI on September 23, 2026 at 00:22 UTC.

Remediation

Vendor Solution

Upgrade to version 3.5.4.


OpenCVE Recommended Actions

  • Upgrade the Apex NVR firmware to version 3.5.4 or later.
  • Restrict physical access to the NVR console, ensuring that only authorized personnel can interact with the device.
  • If the password‑reset function must remain available, limit its use to authenticated users and monitor for abnormal reset activity.

Generated by OpenCVE AI on September 23, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Offline Unlock-Code Forgery Allows Administrator Password Reset

Tue, 22 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
Weaknesses CWE-330
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Securifera

Published:

Updated: 2026-09-22T23:19:15.980Z

Reserved: 2026-09-17T12:03:24.121Z

Link: CVE-2026-92930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T00:17:01.080

Modified: 2026-09-23T00:17:01.080

Link: CVE-2026-92930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T00:30:18Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values