CVE-2026-68950: Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Where FTP is reachable, restrict network access to the FTP service (ftpd) to trusted hosts only to reduce exposure to remote root file access enabled by the hard-coded credentials vulnerability.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems in the affected Digital Watchdog VMAX DVR and NVR product lineups are exposed where their FTP service is reachable by an attacker. The vector is adjacent-network access, so exposure depends on FTP reachability from the attacker’s network position.
What level of access does an attacker need?
No privileges or user interaction are required. An attacker needs adjacent-network access to a reachable FTP service and can use the hard-coded credentials to run ftpd as root.
What is the likely impact if exploitation succeeds?
Successful exploitation provides remote root file access through FTP. This can affect confidentiality, integrity, and availability of files accessible with root privileges.