Impact
The issue is an operating-system command injection flaw in the recbackup module of OpenEye Apex Network Video Recorder firmware. An authenticated administrator can craft backup‑area configuration input that is directly passed to a shell command, enabling arbitrary command execution with the privileges of the nvr user. This flaw falls under CWE‑78, allowing an attacker to read, modify, or delete data and to gain control over the device's operating system.
Affected Systems
Affected products are OpenEye Apex Network Video Recorder firmware versions 3.2.9.376 and all earlier releases dating back to firmware 2.2.3.4. The vendor recommends upgrading to firmware 3.5.4 to remediate the vulnerability.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate to high severity vulnerability. Exploitation requires authenticated administrative access, meaning that attackers with privileged credentials can fully compromise the device. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation in the wild. Nevertheless, the potential impact of code execution makes timely remediation important, especially in environments where administrative accounts may be accessible over the network.
OpenCVE Enrichment