Upgrade to version 3.5.4.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 3.5.4.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openeye
Openeye apex Network Video Recorder (nvr) |
|
| Vendors & Products |
Openeye
Openeye apex Network Video Recorder (nvr) |
Wed, 23 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hardcoded Recovery Account Allows Unauthenticated Password Reset in OpenEye Apex NVR |
Tue, 22 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide normal administrator access; additional vulnerabilities are required to obtain an administrator takeover. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4. | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Securifera
Published:
Updated: 2026-09-23T14:59:42.680Z
Reserved: 2026-09-17T12:03:24.121Z
Link: CVE-2026-92928
Updated: 2026-09-23T14:59:37.004Z
Status : Received
Published: 2026-09-23T00:16:59.773
Modified: 2026-09-23T15:17:29.703
Link: CVE-2026-92928
No data.
OpenCVE Enrichment
Updated: 2026-09-23T09:11:17Z
-
CWE-798
Use of Hard-coded Credentials