CVE-2026-66887

Summary

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

Affected Software

VendorProductVersion RangeStatus
Digital WatchdogVMAX A1 G4 DVRAllaffected
Digital WatchdogVMAX IP G4 NVRAllaffected
Digital WatchdogVMAX A1 PLUSAllaffected
Digital WatchdogVA1G4 RecorderAllaffected
Digital WatchdogVG4 RecorderAllaffected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

References