CVE-2026-92930 Details
Description
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4.
A vulnerability exists in OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376, allowing an attacker with physical-console access to forge a valid administrator password-reset unlock code. This is possible because the password-reset design lacks a per-device secret or server-side cryptographic material. The forged unlock code can be used to reset the administrator password. This vulnerability has been present since at least firmware 2.2.3.4.
Users are advised to upgrade to OpenEye Apex Server Software version 3.5.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.openeye.net/updates/issue-alerts/1060 | [email protected] | AdvisoryRemedyVendor |
| https://www.securifera.com/advisories/ | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-330 | Use of Insufficiently Random Values | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenEye Apex Network Video Recorder | >= 2.2.3.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion