Predictable Web Session Token Vulnerability in Digital Watchdog Products
CVE-2026-66372

7.6HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-66372?

The vulnerability arises from the use of insufficiently random values in the generation of web session tokens within various Digital Watchdog products. This leads to predictable session tokens, compromising the integrity of the session management process. The limited entropy of the generated tokens bounds them to the seed space, making it feasible for an attacker to predict valid session tokens and allowing unauthorized access to sensitive functionalities.

Affected Version(s)

VA1G4 Recorder All

VG4 Recorder All

VMAX A1 G4 DVR All

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scot Berner of TrustedSec reported this vulnerability to CISA.
.