## Overview
KGUARD DVR devices running vulnerable firmware expose a critical system command execution service. This service is accessible on all network interfaces without authentication. Remote attackers can exploit this vulnerability to execute arbitrary commands on the device.
## Technical Details
The vulnerability, tracked as CVE-2026-87827, affects firmware versions dating back to 2016. Devices with this flaw include models D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, and several D97xx, D98xx, and D99xx variants. Firmware released after 2017 mitigates the issue by restricting access to the localhost interface (127.0.0.1).
The vulnerability has been actively exploited by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets. These botnets use the exploit for malware propagation and DDoS attacks. The exploit is also included in some versions of rapperbot.
## Impact
Successful exploitation of CVE-2026-87827 can lead to complete compromise of the affected DVR devices. Attackers can gain control over the devices, potentially turning them into part of a botnet for further malicious activities. The lack of authentication for the vulnerable service significantly increases the risk.
## Mitigation
Defenders should update KGUARD DVR firmware immediately to the latest version available. This will close the vulnerability by restricting the affected service to the localhost interface. Regularly check for firmware updates and monitor network traffic for unusual activity to detect potential exploitation attempts.
CSURFACE Threat Sensor