CVE-2026-0853
Unknown
Unknown - Not Provided
Sensitive Data Exposure in A-Plus NVRs via Debug Page Access
Publication date: 2026-01-12
Last updated on: 2026-01-12
Assigner: TWCERT/CC
Description
Description
Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access the debug page and obtain device status information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| a-plus_video_technologies | nvr | to 2.2.0 (exc) |
| jingzhan_video_technology | nvr | to 2.2.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-497 | The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. |