CVE-2026-92929 Details
Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
A vulnerability exists in OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376, where the application improperly trusts the X-Forwarded-For header from clients. This flaw allows an unauthenticated remote attacker to spoof a loopback address, circumventing local-connection-only security measures on the affected non-TLS web interfaces. As a result, sensitive configuration information can be disclosed. This design flaw has been present since at least firmware 2.2.3.4.
Users are advised to upgrade to OpenEye Apex Server Software version 3.5.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.openeye.net/updates/issue-alerts/1059 | [email protected] | AdvisoryRemedyVendor |
| https://www.securifera.com/advisories/ | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenEye Apex Network Video Recorder | >= 2.2.3.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion