CVE-2026-87827

10.0

KGUARD · DVR (Digital Video Recorder)

KGUARD DVR devices expose a command execution service on all network interfaces without authentication, allowing remote attackers to execute arbitrary system commands and compromise the device.

Executive summary

A critical, unauthenticated remote code execution vulnerability in legacy KGUARD DVR firmware is currently being actively exploited by botnets to facilitate large-scale DDoS attacks.

Vulnerability

The device exposes a system command execution service on all network interfaces (0.0.0.0) without requiring authentication, allowing any unauthenticated remote attacker with network access to execute arbitrary commands.

Business impact

The vulnerability carries a CVSS score of 10.0, reflecting the highest level of risk. Successful exploitation allows an attacker to gain complete control over the DVR device, resulting in total system compromise. Beyond the loss of surveillance capabilities and data confidentiality, these compromised devices are being co-opted into massive botnets, which can lead to significant reputational damage and potential legal liability if the organization's infrastructure is used to launch downstream DDoS attacks against third parties.

Remediation

Immediate Action: Disconnect affected DVR units from the public internet immediately. If the device cannot be updated to a firmware version released after 2017, it must be isolated behind a strictly configured firewall or removed from service entirely.

Proactive Monitoring: Inspect network traffic for unauthorized inbound connections directed at the DVR management ports. Monitor for unusual CPU spikes or unexpected outbound traffic patterns consistent with botnet signaling or DDoS participation.

Compensating Controls: Implement an aggressive access control list on the network perimeter to restrict access to the DVR management interface to known, trusted management IP addresses only. A Web Application Firewall or network-level Intrusion Prevention System should be configured to drop suspicious command injection payloads.

Exploitation status

Public Exploit Available: Yes (The exploit is integrated into the rapperbot malware and documented in public research by Netlab 360).

Analyst recommendation

The severity of this vulnerability cannot be overstated, as it is actively weaponized and poses an immediate threat to network integrity. Organizations still utilizing legacy KGUARD DVR hardware must prioritize the isolation or decommissioning of these devices. Applying the vendor-provided firmware update is the only definitive technical resolution, and failure to act leaves the environment vulnerable to complete takeover and integration into malicious botnet infrastructure.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources