CVE-2026-68953
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Digital Watchdog | VMAX A1 G4 DVR | All | affected |
| Digital Watchdog | VMAX IP G4 NVR | All | affected |
| Digital Watchdog | VMAX A1 PLUS | All | affected |
| Digital Watchdog | VA1G4 Recorder | All | affected |
| Digital Watchdog | VG4 Recorder | All | affected |
Weaknesses
- CWE-306: CWE-306 Missing authentication for critical function
References
- https://digital-watchdog.com/downloads/
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.