CVE-2026-92930
Received Received - Intake

Offline Password Reset Bypass in OpenEye Apex NVR

Vulnerability report for CVE-2026-92930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Securifera, Inc.

Description

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openeye apex_network_video_recorder From 3.5.4 (inc)
openeye apex_network_video_recorder From 2.2.3.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 has a password-reset mechanism that does not use a unique per-device secret or server-side cryptographic material. This allows an attacker with physical access to the device and knowledge of the password-reset process to generate a valid unlock code offline and reset the administrator password without authorization.

Detection Guidance

This vulnerability requires physical access to the device and access to the password-reset workflow. Detection is not possible remotely via commands. Check firmware version against 3.5.4 or later to confirm patch status.

Impact Analysis

An attacker could gain full administrative control over the NVR device by resetting the password. This could allow unauthorized access to video feeds, device settings, and stored recordings, compromising privacy and security of the surveillance system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive video data, potentially violating privacy and data protection requirements under GDPR, HIPAA, or other regulations. Organizations using affected firmware may face compliance violations if proper safeguards are not implemented.

Mitigation Strategies

Upgrade to Apex Server Software version 3.5.4 or later to resolve the vulnerability. Ensure firmware is updated promptly as the issue has been fixed in this version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart