Home

Description

Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access the debug page and obtain device status information.

PUBLISHED Reserved 2026-01-12 | Published 2026-01-12 | Updated 2026-01-12 | Assigner twcert




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

References

www.twcert.org.tw/tw/cp-132-10620-527f1-1.html third-party-advisory

www.twcert.org.tw/en/cp-139-10621-55584-2.html third-party-advisory

cve.org (CVE-2026-0853)

nvd.nist.gov (CVE-2026-0853)

Download JSON