CVE-2026-94367
Received Received - Intake

OS Command Injection in OpenEye Apex NVR Firmware

Vulnerability report for CVE-2026-94367, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Securifera, Inc.

Description

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
openeye apex_network_video_recorder 3.2.9.376
openeye apex_network_video_recorder 3.5.4
openeye apex_server_software 3.4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 has an OS command injection flaw in the recbackup component. An authenticated admin can inject malicious input into backup-area configuration settings, which is then executed as a shell command with the privileges of the nvr user. This flaw has existed since at least firmware version 2.2.3.4.

Detection Guidance

To detect this vulnerability, check if your OpenEye Apex NVR firmware version is below 3.5.4. Verify the version via the web interface or CLI. Search for unauthorized backup-area configuration changes or unexpected shell commands in logs. Monitor network traffic for unusual outbound connections from the NVR.

Impact Analysis

An attacker with admin access could execute arbitrary commands on the system, potentially gaining control over the NVR, accessing sensitive data, disrupting video surveillance, or using the device as a pivot point to attack other systems on the network.

Compliance Impact

This vulnerability allows authenticated administrators to execute arbitrary commands with elevated privileges, potentially leading to unauthorized access or data exfiltration. Such risks could violate compliance requirements under GDPR (data protection) and HIPAA (health data security) by enabling unauthorized access to sensitive data.

Mitigation Strategies

Upgrade to Apex Server Software version 3.4.3 or later immediately to resolve the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94367. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart