CVE-2026-92928

Summary

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4.

Upgrade to version 3.5.4.

Affected Software

VendorProductVersion RangeStatus
OpenEyeApex Network Video Recorder (NVR)3.2.9.376affected

Weaknesses

  • CWE-798: CWE-798: Use of Hard-coded Credentials

References