Executive brief
OpenEye Apex Network Video Recorder (NVR) is a video surveillance device used to store and manage security camera feeds. The password-reset mechanism uses an unlock code that can be forged offline by an attacker with physical console access, allowing unauthorized administrator account takeover. This vulnerability has existed since at least firmware version 2.2.3.4.
Technical details
The vulnerability exists in the administrator password-reset workflow, which uses a static unlock-code design lacking per-device secrets or server-side cryptographic material. An attacker with physical console access to the NVR can forge a valid unlock code offline and use it to reset the administrator password, requiring physical access to the device and knowledge of the privileged password-reset workflow.
Affected products
- OpenEye Apex Network Video Recorder (NVR) 2.2.3.4 through 3.2.9.376
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Apex Server Software version 3.5.4 and later