CVE-2026-6824: CP Plus 8 Ch. Network Video Recorder Cross-site Scripting
A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potential session hijacking, unauthorized actions, or data theft.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CP Plus 1xxx series NVR devicesto a version that resolves this vulnerability.Fixed in CP-UNR-AxxxMars_PN_15_Q_00_V1.00.14.01.T.260326
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6824?
CVE-2026-6824 has a high severity rating of 8.4.
How do I fix CVE-2026-6824?
To resolve CVE-2026-6824, CP Plus recommends updating the firmware to the latest version.
What type of vulnerability is CVE-2026-6824?
CVE-2026-6824 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-6824?
CVE-2026-6824 affects certain models in the CP Plus 1xxx series 8 Ch. Network Video Recorder.
What are the potential impacts of CVE-2026-6824?
If exploited, CVE-2026-6824 allows attackers to inject and store malicious scripts on the device backend.