Government Advisory

Critical Flaws Found in Digital Watchdog VMAX Surveillance Recorders

CISA · 15 Sept 2026
Key Takeaway If your business uses Digital Watchdog VMAX surveillance recorders, isolate them from the internet, change any default credentials, and apply vendor updates as soon as they are available.

CISA has issued an advisory covering multiple critical vulnerabilities in Digital Watchdog VMAX DVR and NVR product lines, including the A1 G4, IP G4, A1 PLUS, VA1G4 and VG4 recorders. The flaws include missing authentication for critical functions, hard-coded credentials, missing authorization checks and a predictable random number generator, with one vulnerability rated 9.6 out of 10 for severity.

Successful exploitation could give an attacker full administrative control of an affected device. This would allow them to view live and recorded video footage, change device settings, or use the recorder as a foothold to move further into a business's network. These devices are used across commercial facilities, healthcare, transport and government sites worldwide, meaning many organisations relying on them for physical security could be exposed.

Any business using Digital Watchdog VMAX DVR or NVR equipment for CCTV or surveillance should check with the vendor for patches or firmware updates and ensure these devices are not directly exposed to the internet.

CISA advisory IoT security surveillance systems critical vulnerability Digital Watchdog

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.