VulnSea

Digital Watchdog has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 8.8 (high), with 2 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
6 prev 0

Products

  • VMAX A1 G4 DVR 6
6
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Digital Watchdog vulnerabilities

CVEs affecting Digital Watchdog, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-66887Critical· 9.6
1w ago

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

MidnightDigital Watchdog · VMAX A1 G4 DVREPSS 0.20%via NVD
CVE-2026-66372Medium· 6.8
1w ago

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.20%via NVD
CVE-2026-68953Medium· 6.5
1w ago

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.37%via NVD
CVE-2026-68070High· 8.8
1w ago

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.27%via NVD
CVE-2026-68950High· 8.8
1w ago

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.22%via NVD
CVE-2026-66890Critical· 9.6
1w ago

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

MidnightDigital Watchdog · VMAX A1 G4 DVREPSS 0.20%via NVD
Digital Watchdog vulnerabilities (CVEs) · VulnSea