PatchSiren cyber security CVE debrief
CVE-2026-6824 CP Plus CVE debrief
A stored cross-site scripting (XSS) vulnerability in certain 1xxx series Network Video Recorder (NVR) devices allows authenticated attackers with high privileges to inject malicious scripts that persist on the device backend. When administrators or users subsequently access affected pages, the stored scripts execute in their browsers, potentially enabling session hijacking, unauthorized actions, or data theft. The vulnerability stems from insufficient sanitization of user-supplied input in specific functional modules. CISA published this advisory on May 29, 2026 (ICS Advisory ICSA-26-148-05). The CVSS 3.1 vector indicates network attack vector, low attack complexity, high privileges required, user interaction required, and changed scope with high impacts to confidentiality, integrity, and availability.
- Vendor
- CP Plus
- Product
- CP-UNR-108F1 Hardware
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-28
Who should care
Organizations deploying 1xxx series NVR devices for video surveillance; OT/ICS security teams managing physical security systems; facility security administrators; critical infrastructure operators with integrated video management systems
Technical summary
The vulnerability exists in specific functional modules of 1xxx series NVR devices where user-supplied input is insufficiently sanitized before persistent storage. An attacker with high privileges (PR:H) can inject malicious scripts that are stored on the device backend. Subsequent access by administrators or users triggers execution of these scripts in the browser context (UI:R). The changed scope (S:C) indicates impact beyond the vulnerable component. The CVSS 3.1 score of 8.4 reflects severe potential impacts to confidentiality, integrity, and availability (all rated HIGH) despite the high privilege requirement, due to the network accessibility and low attack complexity.
Defensive priority
HIGH
Recommended defensive actions
- Apply vendor firmware updates for affected 1xxx series NVR devices when available, per CISA ICS-CERT guidance
- Restrict network access to NVR administrative interfaces to trusted management networks only
- Implement multi-factor authentication for all administrative accounts on affected NVR systems
- Monitor for anomalous administrative sessions or unexpected script execution in browser-based management consoles
- Review and validate input sanitization in custom integrations with NVR web interfaces
- Consider network segmentation to isolate NVR devices from untrusted networks and user workstations
Evidence notes
Primary source is CISA ICS-CERT advisory ICSA-26-148-05. The CVE description and CVSS vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H) are sourced from NVD. CWE-79 (Improper Neutralization of Input During Web Page Generation) is identified as the primary weakness. Vendor identification remains uncertain—'Unknown Vendor' with low confidence based on reference domain analysis; the product appears to be 1xxx series NVR devices.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6824 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6824
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6824 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6824
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://drive.google.com/file/d/1Ctxdp55UtlrQY7CSepkImM9zFgdcuCyL/view
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-05.json
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-05
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.