OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connectio
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenEye | Apex Network Video Recorder (NVR) | 3.2.9.376 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94367 | 7.2 HIGH | OpenEye Apex NVR 3.2.9.376 命令注入漏洞 |
| CVE-2026-92928 | 6.5 MEDIUM | OpenEye Apex NVR 3.2.9.376硬编码恢复账户漏洞 |
| CVE-2026-92930 | 6.2 MEDIUM | OpenEye Apex NVR 3.2.9.376 管理员密码重置缺陷 |
No comments yet