Authentication Bypass in OpenEye Apex NVR Firmware
CVE-2026-92929
5.3MEDIUM
What is CVE-2026-92929?
The OpenEye Apex Network Video Recorder firmware version 3.2.9.376 has a vulnerability related to the way it handles the X-Forwarded-For header provided by clients. An attacker can exploit this flaw to bypass local security measures that restrict access to sensitive configuration information through non-TLS web interfaces. This threat can lead to unauthorized exposure of data, affecting the overall security of the device. The flaw has existed since at least firmware version 2.2.3.4, emphasizing the importance of timely firmware updates. Users are recommended to upgrade to version 3.5.4 to mitigate risks.
Affected Version(s)
Apex Network Video Recorder (NVR) 3.2.9.376
