CVE-2026-66372: Predictable Seed in Pseudo-Random Number Generator (PRNG) in Digital Watchdog VMAX DVR and NVR Product Lineups
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is reachable over an adjacent network and does not require prior privileges or user interaction. Exploitation is rated high complexity, and it relies on predicting web session tokens from insufficiently random values.
What security impact could successful exploitation have?
Successful token prediction can expose the confidentiality and integrity of affected systems. The supplied scoring indicates no direct availability impact.
Which deployments are exposed?
Digital Watchdog VMAX DVR and VMAX NVR product lineups are identified as affected. The provided data does not specify affected versions, configurations, or whether exposure requires web session access to be enabled.