Executive brief
OpenEye Apex is a network video recorder that stores and manages surveillance footage from security cameras. An authenticated administrator can inject arbitrary operating system commands through backup configuration settings, gaining unauthorized code execution on the recorder with system-level privileges. This could allow an attacker with admin credentials to gain control of the entire surveillance system and access sensitive recordings.
Technical details
The recbackup component fails to properly sanitize backup-area configuration input before passing it to a shell command, enabling OS command injection. An authenticated administrator account is required to exploit this vulnerability. Successful exploitation allows arbitrary command execution with nvr user privileges on the device. A fix is available in firmware 3.4.3 and later (advisory notes 3.5.4 as current).
Affected products
- OpenEye Apex Network Video Recorder 3.2.9.376 and earlier (vulnerable since at least 2.2.3.4); fixed in 3.4.3 and later
Timeline
- 2026-09-23: disclosed
- 2026: patched: Fixed in firmware 3.4.3 and later