Executive brief
Affected surveillance and network management products fail to properly validate user authorization and session credentials when processing configuration or state-changing commands. This allows an unauthenticated or malicious actor to modify system settings, access sensitive data, or disrupt operations without proper access controls.
Technical details
This vulnerability is an authorization bypass affecting CGI (Common Gateway Interface) endpoints that handle state-changing operations. The root cause is the absence of authorization checks and session validation on endpoints that should require authenticated access. An unauthenticated attacker can send network requests directly to vulnerable CGI endpoints without providing valid session credentials or authentication tokens. Successful exploitation allows the attacker to execute arbitrary configuration changes, modify system state, and potentially access restricted information. Patches are expected to be available through vendor security updates.
Affected products
- Digital Watchdog Digital Watchdog Surveillance System <UNKNOWN>
Timeline
- 2026-09-15: disclosed
- other: ICSA advisory ICSA-26-258-01 published