CVE-2026-87827
Deferred Deferred - Pending Action

Unauthenticated Remote Command Execution in KGUARD DVR Firmware

Vulnerability report for CVE-2026-87827, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: CIRCL

Description

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version ofΒ rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kguard dvr *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects certain KGUARD DVR devices with vulnerable firmware. It exposes a service on all network interfaces that allows remote unauthenticated attackers to execute arbitrary system commands without authentication. This can lead to complete compromise of the affected DVR device.

Detection Guidance

Check if the KGUARD DVR service is exposed on all network interfaces by scanning for open ports. Use commands like 'nmap -p- <target_IP>' to identify open ports. Verify if the service is accessible from external networks by testing connections to the exposed port. Inspect network traffic for unusual activity or connections to known malicious IPs associated with Mirai botnets.

Impact Analysis

If you own or use an affected KGUARD DVR device with outdated firmware, attackers can exploit this to take full control of your device. This may result in malware propagation, participation in DDoS attacks, or unauthorized access to your network and data.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, loss of trust, and reputational damage if such breaches occur due to unpatched devices.

Mitigation Strategies

Isolate the affected DVR device from external networks by placing it behind a firewall or in a DMZ. Update the firmware to a version released after 2017, which restricts the vulnerable service to localhost. If no update is available, disable the vulnerable service entirely. Monitor network traffic for signs of exploitation or botnet activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87827. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart