CVE-2026-68070: Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
Published Sep 15, 2026
·Updated
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
Event History
Sep 15, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need valid credentials or user interaction to exploit this issue?
No. The vulnerability is rated with no privileges required and no user interaction required.
2
What level of access could successful exploitation provide?
An attacker could run commands as root, with received bytes passed directly to a system command. This could affect confidentiality, integrity, and availability.
3
What network position does an attacker need?
The attack vector is adjacent network, meaning the attacker must be on a network adjacent to the affected device rather than exploiting it solely through local access.