Junglewise Threat Intelligence

CVE-2026-68950: Digital Watchdog surveillance hard-coded credentials in ftpd

CVE-2026-68950 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Digital Watchdog surveillance systems contain hard-coded FTP credentials that allow remote attackers to gain root-level access to the file system when the FTP service is exposed to the network. An attacker can leverage these credentials to read, modify, or delete video recordings and system files, compromising the integrity and availability of critical surveillance infrastructure.

Technical details

The vulnerability is a hard-coded credential weakness in the ftpd service running on affected Digital Watchdog surveillance products. An attacker with network access to the FTP port can authenticate using embedded credentials and execute commands as the root user. No authentication bypass is required—the credentials are fixed in the application code. The attack vector is network-based and requires only that the FTP service be reachable; no user interaction is needed. Successful exploitation grants full remote file system access and command execution with administrative privileges. Patch availability is not specified in the advisory.

Affected products

  • Digital Watchdog Surveillance Products <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References