CVE-2026-68953: Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product Lineups
Published Sep 15, 2026
·Updated
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
Event History
Sep 15, 2026
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Digital Watchdog VMAX DVR and NVR devices are exposed if an attacker can send HTTP(S) requests to the device. The issue can be exploited remotely without prior authentication.
2
What does an attacker need to exploit the issue?
An attacker needs network access to the affected device's HTTP(S) service and must send crafted requests. No credentials or user interaction are required.
3
What information can be obtained through successful exploitation?
Successful exploitation can disclose sensitive device information, including administrator credentials in plaintext.