Password Reset Vulnerability in OpenEye Apex NVR Firmware
CVE-2026-92930

6.2MEDIUM

Key Information:

Vendor

Openeye

Vendor
CVE Published:
22 September 2026

What is CVE-2026-92930?

The OpenEye Apex Network Video Recorder (NVR) firmware is exposed to a security flaw due to a poorly designed password-reset mechanism. Specifically, firmware version 3.2.9.376 allows an attacker with physical console access to utilize the privileged password-reset process to generate a valid unlock code. This unlock code can be forged offline, permitting unauthorized individuals to reset the administrator password. This vulnerability is present in previous firmware versions as well, emphasizing the importance of updating to the recommended version 3.5.4 to mitigate any potential security threats.

Affected Version(s)

Apex Network Video Recorder (NVR) 3.2.9.376

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Wincey (@rwincey, Securifera)
.