CVE-2026-92930: Medium severity OpenEye Apex Network Video Recorder (NVR) vulnerability

Published Sep 22, 2026
·
Updated

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4.

Upgrade to version 3.5.4.

Affected Software

1 affected component
OpenEye Apex Network Video Recorder (NVR)>=2.2.3.4<3.5.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenEye Apex Network Video Recorder (NVR) firmware to a version that resolves this vulnerability.

    Fixed in 3.5.4

Event History

Sep 22, 2026
CVE Published
via MITRE·11:10 PM
Data Sourced
via MITRE·11:10 PM
RemedyDescriptionSeverityWeakness
Sep 23, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are potentially affected?

OpenEye Apex NVR systems running firmware 3.2.9.376 are affected, and the vulnerable password-reset design has existed since at least firmware 2.2.3.4. Upgrade to firmware version 3.5.4.

2

What access does an attacker need to exploit this issue?

An attacker needs physical-console access to the NVR and access to the privileged password-reset workflow. They can then generate a valid unlock code offline and reset the administrator password.

3

Are remotely accessible systems exposed through this flaw alone?

The provided information describes a physical-console attack path and does not identify a remote exploitation path. Physical access controls around the NVR are therefore relevant to exposure.

4

What can be done before the firmware is upgraded?

Restrict physical-console access to the NVR and limit access to the privileged password-reset workflow. These controls reduce the ability to generate and use forged unlock codes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203