CVE-2026-92928
6.5OpenEye · Apex Network Video Recorder (NVR)
OpenEye Apex NVR firmware contains a hardcoded recovery account with shared, immutable credentials that allow unauthenticated remote access to the password reset workflow.
Executive summary
A hardcoded recovery account in OpenEye Apex NVR firmware exposes systems to unauthenticated remote access, requiring immediate firmware updates to mitigate the risk of unauthorized authentication.
Vulnerability
This vulnerability involves the use of hardcoded credentials (CWE-798) within a recovery account that cannot be modified or disabled. An unauthenticated remote attacker can leverage this account to access the password-reset workflow, facilitating potential unauthorized administrative takeover when combined with secondary vulnerabilities.
Business impact
While the CVSS score is 6.5, the presence of hardcoded credentials in security-sensitive hardware creates significant risk for physical and digital security. Unauthorized access to the password reset mechanism could allow an attacker to bypass authentication controls, leading to total compromise of video surveillance infrastructure, loss of sensitive footage, and potential lateral movement into the broader corporate network.
Remediation
Immediate Action: Upgrade all affected OpenEye Apex NVR devices to firmware version 3.5.4 or later immediately.
Proactive Monitoring: Review device access logs for unusual login activity or repeated attempts to trigger the password-reset workflow, particularly from unauthorized or unexpected IP addresses.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to restrict access to the NVR management interface to known, trusted administrative workstations only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The reliance on hardcoded credentials represents a fundamental security failure that must be addressed by applying the vendor-provided firmware update. Administrators should prioritize this update across all deployed units to eliminate the static recovery account and prevent unauthorized access to the password reset process.
More OpenEye CVEs
History
- Analyst report written
Sources
Originally found and disclosed by Ryan Wincey (@rwincey, Securifera), per the CVE Program record.