Digital Watchdog VMAX DVR/NVR Hardcoded FTP Credentials and Missing Authorization on State-Changing CGIs

Release Date: 15th September 2026 (Added 16 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Digital Watchdog VMAX DVR/NVR video surveillance recorders, including government facilities, businesses, and other sites using these devices for CCTV/physical security monitoring. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-66890 and CVE-2026-66887 are two critical vulnerabilities in the Digital Watchdog VMAX A1 G4 DVR, VMAX IP G4 NVR, VMAX A1 PLUS, VA1G4 Recorder, and VG4 Recorder product lines. Digital Watchdog is a well-established video surveillance (CCTV) brand, particularly in the budget/analog recorder segment, distributed in the Pacific region through Australian security distributors including CRK Security and Ness Corporation.

CVE-2026-66890 is the use of hardcoded credentials that could allow an attacker with network access to the device's FTP service to remotely access files with root privileges.

CVE-2026-66887 is a missing-authorization flaw in which state-changing CGI endpoints on the device do not perform session checks, allowing an attacker to make administrative changes without authenticating.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-66890
  2. https://www.cve.org/CVERecord?id=CVE-2026-66887
  3. https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01