PT-2026-97114 · Openeye · Apex Network Video Recorder
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEye Apex Network Video Recorder versions 2.2.3.4 through 3.2.9.376
Description
An OS command injection issue exists in the
recbackup component. An authenticated administrator can provide specially crafted backup-area configuration input that is passed to a shell command, enabling the execution of arbitrary commands with the privileges of the nvr user.Recommendations
Upgrade to version 3.5.4.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apex Network Video Recorder