Authorization Flaws in State-Changing Interfaces for Digital Watchdog Products
CVE-2026-66887
9.4CRITICAL
What is CVE-2026-66887?
The identified vulnerability in Digital Watchdog products occurs due to inadequate authorization checks on state-changing CGI operations. This oversight may allow unauthorized users to manipulate system states without proper session validation, potentially leading to significant security risks. Users should be aware that this vulnerability poses a threat as it could be exploited to gain unauthorized control over the affected devices.
Affected Version(s)
VA1G4 Recorder All
VG4 Recorder All
VMAX A1 G4 DVR All
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Scot Berner of TrustedSec reported this vulnerability to CISA.
