CVE-2026-87827 Details
Description
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.
A vulnerability in certain KGUARD DVR models exposes a remote command execution service on all network interfaces, without authentication. This flaw allows attackers to execute arbitrary system commands, potentially leading to a complete compromise of the DVR. The issue affects devices with firmware from 2016, while versions released after 2017 have reportedly fixed the problem by limiting the service to the localhost interface. The vulnerability has been actively exploited by the Mirai_ptea and Mirai_aurora botnets for malware distribution and DDoS attacks.
Users are advised to update to KGUARD DVR firmware released after 2017, which addresses the vulnerability by restricting the command execution service to the localhost interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.netlab.360.com/mirai_ptea-botnet-is-exploiting-undisclosed-kguard-dvr-vulnerability-en/ | CIRCL | BundleExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| KGUARD D1004NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1008NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1016NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1104 | < 2017 |
CPE
Remediation
| |
| KGUARD D1104NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1108NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1116 | < 2017 |
CPE
Remediation
| |
| KGUARD D1116NR | < 2017 |
CPE
Remediation
| |
| KGUARD D1132NR | < 2017 |
CPE
Remediation
| |
| KGUARD D2116NR | < 2017 |
CPE
Remediation
| |
| KGUARD D97xx | < 2017 |
CPE
Remediation
| |
| KGUARD D98xx | < 2017 |
CPE
Remediation
| |
| KGUARD D99xx | < 2017 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | CIRCL |
Volerion