Back

HIGH

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup

Published Sep 22, 2026

Description

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4.

This vulnerability is resolved in OpenEye Apex version 3.4.3.

Affected products

Remediation

Vendor solution

Upgrade to OpenEye Apex version 3.4.3.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Securifera
Published Sep 22, 2026
Updated Sep 26, 2026
Reserved Sep 21, 2026
CISA Vulnrichment
Updated Sep 23, 2026
NVD
Status Received
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Securifera
Published Sep 22, 2026
Updated Sep 26, 2026
Exploited since n/a
EUVD-2026-84985