Executive brief
OpenEye Apex Network Video Recorder is a video surveillance system that records and manages security camera feeds. The firmware trusts client-supplied X-Forwarded-For headers to determine request origin, allowing remote attackers to spoof a local connection and bypass security controls that restrict access to sensitive features. An attacker can exploit this to extract system configuration details without authentication.
Technical details
The NVR firmware fails to validate the X-Forwarded-For HTTP header, allowing unauthenticated remote attackers to spoof a loopback address and bypass local-connection-only access controls on non-TLS web interfaces. This design flaw has existed since firmware 2.2.3.4. Exploitation requires only network access to the unencrypted web interface and results in unauthorized disclosure of configuration information.
Affected products
- OpenEye Apex Network Video Recorder 3.2.9.376 and earlier (vulnerable since at least 2.2.3.4); fixed in 3.5.4 and later
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Version 3.5.4 and later