CVE-2026-92930: Medium severity OpenEye Apex Network Video Recorder (NVR) vulnerability
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4.
Upgrade to version 3.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenEye Apex Network Video Recorder (NVR) firmwareto a version that resolves this vulnerability.Fixed in 3.5.4
Event History
Frequently Asked Questions
Which systems are potentially affected?
OpenEye Apex NVR systems running firmware 3.2.9.376 are affected, and the vulnerable password-reset design has existed since at least firmware 2.2.3.4. Upgrade to firmware version 3.5.4.
What access does an attacker need to exploit this issue?
An attacker needs physical-console access to the NVR and access to the privileged password-reset workflow. They can then generate a valid unlock code offline and reset the administrator password.
Are remotely accessible systems exposed through this flaw alone?
The provided information describes a physical-console attack path and does not identify a remote exploitation path. Physical access controls around the NVR are therefore relevant to exposure.
What can be done before the firmware is upgraded?
Restrict physical-console access to the NVR and limit access to the privileged password-reset workflow. These controls reduce the ability to generate and use forged unlock codes.