CVE-2026-68950
8.8Digital Watchdog · VMAX A1 G4 DVR
Digital Watchdog VMAX series recorders contain hard-coded credentials that allow unauthenticated attackers to gain root access to the ftpd service and access the underlying file system.
Executive summary
The Digital Watchdog VMAX series of recording devices is vulnerable to a critical hard-coded credential flaw that permits unauthenticated remote root file access.
Vulnerability
The device uses hard-coded credentials (CWE-798) that grant an unauthenticated attacker the ability to execute the ftpd service with root privileges, leading to unauthorized file system access.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational security, as it grants full administrative access to the recording device. Given the CVSS score of 8.8, this vulnerability is classified as high severity, potentially leading to unauthorized surveillance access, persistent device compromise, and the pivot point for further network infiltration.
Remediation
Immediate Action: Download and install the latest firmware updates provided by Digital Watchdog at https://digital-watchdog.com/downloads/ for all affected recording devices.
Proactive Monitoring: Monitor network logs for unusual FTP traffic or unauthorized connection attempts targeting these specific recording devices.
Compensating Controls: Restrict network access to the FTP management port (typically port 21) via a firewall or network segmentation to ensure the interface is not reachable from untrusted network segments.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a critical security failure in Digital Watchdog recording hardware. Organizations currently utilizing these devices must prioritize the application of the vendor-supplied firmware updates to eliminate the hard-coded credential vulnerability. Failure to remediate this issue leaves surveillance infrastructure and the surrounding network exposed to full administrative compromise.
More Digital Watchdog CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Scot Berner of TrustedSec reported this vulnerability to CISA., per the CVE Program record.