CVE-2026-92928: Medium severity OpenEye Apex Network Video Recorder (NVR) firmware vulnerability
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4.
Upgrade to version 3.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenEye Apex Network Video Recorder (NVR) firmwareto a version that resolves this vulnerability.Fixed in 3.5.4
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated remote exploitation?
OpenEye Apex NVR firmware with the affected recovery-account design is exposed if an attacker can reach its password-reset workflow over the network. The design has been present since at least firmware 2.2.3.4.
Does exploiting this issue by itself give an attacker administrator access?
No. The recovery account can authenticate to the password-reset workflow but does not provide normal administrator access; additional vulnerabilities would be required for an administrator takeover.
Can the recovery credential be mitigated through configuration if an upgrade cannot be applied immediately?
The shared recovery credential cannot be changed, disabled, or rotated. The provided information identifies upgrading to firmware 3.5.4 as the remediation.
How can I determine whether my NVR is affected?
Check the installed Apex NVR firmware version and whether it predates the recommended 3.5.4 upgrade. The vulnerable design is known to exist in firmware going back to at least 2.2.3.4.