Junglewise Threat Intelligence

CVE-2026-68953: Digital Watchdog surveillance device authentication bypass

CVE-2026-68953 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Digital Watchdog surveillance devices contain a flaw that allows unauthenticated attackers to remotely obtain sensitive information, including administrator passwords stored in plaintext. An attacker can exploit this by sending specially crafted HTTP requests without needing valid credentials, potentially leading to complete system compromise and unauthorized access to video surveillance systems.

Technical details

The vulnerability is an authentication bypass in Digital Watchdog surveillance products that fails to properly validate HTTP(S) requests before processing them. Unauthenticated remote attackers can send crafted requests to retrieve sensitive device information, including plaintext administrator credentials. The attack requires network access to the device but no authentication or user interaction. Successful exploitation allows complete disclosure of system credentials and device configuration. Patches are expected from the vendor; refer to https://nvd.nist.gov/vuln/detail/CVE-2026-68953 for remediation details.

Affected products

  • Digital Watchdog Surveillance Devices <UNKNOWN>

Timeline

  • 2026-09-15: disclosed: CVE-2026-68953 published on NVD

References