CVE-2026-92930

6.2

OpenEye · Apex Network Video Recorder (NVR)

OpenEye Apex NVR firmware uses a predictable password-reset unlock code, allowing an attacker with physical access to forge codes and reset the administrator password.

Executive summary

A critical vulnerability in OpenEye Apex Network Video Recorders allows an attacker with physical access to bypass authentication by forging an administrator password-reset code.

Vulnerability

The device uses an insecure password-reset mechanism that lacks per-device secrets or cryptographic validation, enabling offline code forgery. An attacker with physical console access can leverage this design flaw to reset the administrator password and gain full control of the device.

Business impact

Successful exploitation results in a total compromise of the video management system, granting the attacker administrative access to surveillance data and device controls. While the CVSS score is 6.2, the impact is severe for physical security operations, as unauthorized individuals could disable security monitoring or gain access to sensitive visual data. Loss of integrity and confidentiality in security infrastructure poses significant operational and safety risks.

Remediation

Immediate Action: Upgrade the OpenEye Apex NVR firmware to version 3.5.4 or later to implement the secure password-reset logic.

Proactive Monitoring: Review physical access logs and audit device login history for unauthorized administrative sessions or password reset attempts occurring during non-standard hours.

Compensating Controls: Restrict physical access to the NVR console to authorized personnel only and ensure the device is housed in a locked, tamper-evident cabinet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a significant security risk for facilities relying on OpenEye surveillance hardware. Administrators should prioritize the firmware update to version 3.5.4 immediately, as it is the only method to rectify the flawed cryptographic design. Physical security controls should be audited to ensure that unauthorized parties cannot gain the physical access necessary to initiate the attack.

More OpenEye CVEs

History

  1. Analyst report written

Sources

Originally found and disclosed by Ryan Wincey (@rwincey, Securifera), per the CVE Program record.