CISA has issued an ICS advisory covering multiple vulnerabilities across the Digital Watchdog VMAX DVR and NVR product lineups, including VMAX A1 G4, IP G4, A1 PLUS, VA1G4, and VG4 recorders (all versions). The flaws include missing authentication for critical functions, use of hard-coded credentials, missing authorization, and a predictable seed in a pseudo-random number generator. The most severe issue carries a CVSS v3 score of 9.6.
Successful exploitation would let an attacker gain full administrative control of the device, view live and recorded surveillance, change configurations, and use the recorder as a pivot point deeper into the network. The hard-coded credentials and authentication-bypass issues are especially concerning from an identity standpoint, since they defeat access controls entirely without requiring valid user credentials.
What to take away: Surveillance recorders are often overlooked network-connected devices that can serve as an initial foothold. Organizations should inventory affected VMAX devices, restrict them from internet exposure, segment them from AD and core networks, and apply vendor mitigations to prevent them becoming a lateral-movement launchpad.