Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-87827: KGuard DVR allows remote attackers to run commands

CVE-2026-87827 · published 1 month ago
Summary

KGuard DVR devices with older firmware expose a command service that anyone on the network can use without logging in. An attacker could run any command on the DVR, potentially taking full control of the system. Update the DVR to the latest firmware released after 2017 or limit network access to trusted hosts to mitigate the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
kguard kguard_firmware All versions
Original advisory text
KGUARD DVR unauthenticated remote command execution vulnerability
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR.

The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0).

The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions


The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-87827 · MITRE
Track software like this
Free during beta