Junglewise Threat Intelligence

CVE-2026-6824: CP Plus NVR stored XSS in 1xxx series devices

CVE-2026-6824 · Severity: high · CVSS 8.4 · Published 2026-05-29

Vendors: CP Plus.

Executive brief

CP Plus 1xxx series Network Video Recorders (NVR), used for managing security camera footage, are affected by a security flaw that allows attackers to inject malicious scripts into the device's management interface. If an administrator views the compromised page, the attacker could hijack their session, perform unauthorized actions, or steal sensitive data. This could lead to a full compromise of the surveillance system and its recorded data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in CP Plus 1xxx series NVR devices (specifically CP-UNR-108F1) due to insufficient sanitization of user-supplied input in specific functional modules. An attacker with high privileges can inject malicious JavaScript into the device backend. When other authenticated users or administrators navigate to the affected functional pages, the script executes within their browser context. This can result in session hijacking, manipulation of sensitive data, or unauthorized administrative actions. A firmware update (V1.00.14.01.T.260326) has been released to mitigate this issue.

Affected products

  • CP Plus CP-UNR-108F1 Hardware V1.0
  • CP Plus CP-UNR-108F1 Web V3.2.7.128806
  • CP Plus CP-UNR-108F1 System V4.001.00AT009.0.R

Timeline

  • 2026-05-28: advisory: Initial publication by CISA (ICSA-26-148-05)
  • 2026-05-29: disclosed: NVD publication date

References