Upgrade to version 3.5.4.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 3.5.4.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Bypass of Local-Connection-Only Controls via Spoofed X-Forwarded-For Header |
Tue, 22 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS web interfaces and disclose configuration information. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4. | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Securifera
Published:
Updated: 2026-09-22T23:19:15.124Z
Reserved: 2026-09-17T12:03:24.121Z
Link: CVE-2026-92929
No data.
Status : Received
Published: 2026-09-23T00:17:00.897
Modified: 2026-09-23T00:17:00.897
Link: CVE-2026-92929
No data.
OpenCVE Enrichment
Updated: 2026-09-23T00:30:18Z
-
CWE-290
Authentication Bypass by Spoofing