HomeSecurityOpenEye Apex NVR: Three vulnerabilities require an upgrade

OpenEye Apex NVR: Three vulnerabilities require an upgrade

Three new vulnerabilities affect OpenEye Apex NVRs with firmware 3.2.9.376, ranging from bypassing access controls and resetting administrator passwords to executing commands in the operating system. The listings were published on September 22 and 23, 2026, and recommend upgrading to firmware version 3.5.4.

OpenEye Apex NVR network report

The SecNews editorial team identified the relevant entries in the CVE Alert and CVE Feed. The descriptions concern the same model and the same affected version, while the suggested fix is ​​common: installing version 3.5.4 or later.

The range of requirements varies significantly. The first vulnerability can be exploited from the network without an account, the second requires physical access to the console, and the third requires an administrator account. This difference does not negate the overall risk, because recording devices often remain active for long periods of time and are connected to infrastructure that is not monitored daily.

See also: Critical vulnerability in Check Point management allows code execution

OpenEye Apex NVR: The three different weaknesses

CVE -2026-92929 is rated CVSS 5.3 and is related to the validation of the X-Forwarded-For. A remote, unauthenticated attacker can spoof a loopback address and bypass local-only checks on unencrypted web interfaces. The consequence is possible disclosure of configuration information.

CVE -2026-92930 has a CVSS score of 6.2 and concerns the administrator password reset process. The design does not use a per-device secret or other hardware that resides on the server. Therefore, someone with access to the console and the privileged reset flow could generate a valid unlock code offline and change the password.

OpenEye Apex NVR command execution

The most serious of the three is CVE-2026-94367, with CVSS 7.2. The vulnerability is located in the recbackup: an administrator with valid credentials can insert specially configured parameters for the backup area, which result in a shell command. The execution is done with the privileges of the nvr.

The three vulnerabilities share a common affected firmware version, 3.2.9.376, while the descriptions state that the vulnerable design existed since at least version 2.2.3.4. The listings do not document active exploitation or a specific incident; therefore, risk assessment must be based on each installation's exposure and access rights.

For security teams, the combination of these three issues means that a general web-based audit is not enough. It requires inventorying all recorders, verifying firmware, auditing accounts, and examining logs for unexpected connections or changes. OpenEye’s firmware page does not provide specific instructions for the Apex NVR, so administrators should follow the support channel and the instructions that come with the installation.

See also: Check Point VPN vulnerabilities: NCSC warns of imminent exploitation

OpenEye Apex NVR firmware upgrade

What should administrators do?

The basic action for any OpenEye Apex NVR with firmware 3.2.9.376 is to upgrade to version 3.5.4 or later, as stated in the relevant CVE entries. This should be done with a controlled maintenance plan, after confirming the model, current version, and the ability to restore to a safe configuration copy.

Until the upgrade is complete, access to management interfaces should be limited to trusted networks and unencrypted services should not be exposed to the internet. At the same time, check for unexpected changes to accounts, passwords, network settings, and backup jobs, but do not assume that the absence of evidence precludes prior access.

The SecNews technical team recommends recording the upgrade and rechecking permissions after installation. Particular attention is required on devices that manage cameras or critical installations, as a compromised recorder can provide lateral visibility into the network. Maintaining updated firmware remains the most important measure.

See also: Check Point, Kaspersky and Tanium patch critical vulnerabilities

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS