CVE-2026-68953

Summary

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

Affected Software

VendorProductVersion RangeStatus
Digital WatchdogVMAX A1 G4 DVRAllaffected
Digital WatchdogVMAX IP G4 NVRAllaffected
Digital WatchdogVMAX A1 PLUSAllaffected
Digital WatchdogVA1G4 RecorderAllaffected
Digital WatchdogVG4 RecorderAllaffected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function

References