Junglewise Threat Intelligence

CVE-2026-92928: OpenEye Apex Network Video Recorder hardcoded recovery account authentication bypass

CVE-2026-92928 · Severity: medium · CVSS 6.5 · Published 2026-09-23

Technologies: OpenEye Apex Network Video Recorder. Vendors: OpenEye.

Executive brief

OpenEye Apex Network Video Recorder is a surveillance system that records and manages video from security cameras. The firmware contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed or disabled. An attacker with physical access to the device can use this account to trigger a password-reset workflow, potentially gaining administrative control of the system and enabling access to recorded video or system takeover.

Technical details

The vulnerability is a hardcoded credential in an undocumented recovery account present in the password-reset workflow. The account is accessible remotely to the reset mechanism but does not grant normal administrator privileges; additional vulnerabilities are required to escalate to full administrative access. This design flaw has been present in the firmware since at least version 2.2.3.4. Exploitation requires physical or network access to reach the password-reset workflow component.

Affected products

  • OpenEye Apex Network Video Recorder firmware before 3.5.4, including 3.2.9.376 and versions back to at least 2.2.3.4

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fix available in firmware version 3.5.4 and later

References

Related threats