External risk intelligence

KGUARD DVR Unauthenticated System Command Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-87827

The device is a DVR, a product class frequently exposed to the public internet for remote access. The vulnerability exposes a system command service directly on all network interfaces (0.0.0.0) without authentication, making it reachable by any remote attacker capable of reaching the device's network interface.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in certain KGUARD DVR devices, allowing unauthenticated remote attackers to execute arbitrary system commands. This could lead to a complete compromise of the device and has been actively exploited in the wild by botnets for malware propagation and distributed denial-of-service attacks.

  • Unauthenticated command execution on DVRs.
  • Exploited by botnets for malware and DDoS.
  • Confirm device relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach vulnerable KGUARD DVR devices over the network and execute system commands without any authentication. This could lead to the complete compromise of the DVR.

  • Attacker needs network access.
  • Unauthenticated system command execution.
  • Complete device compromise.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability affects certain KGUARD DVR devices, allowing unauthenticated remote attackers with network access to execute arbitrary system commands. This could lead to a complete compromise of the DVR, potentially impacting its core function and any connected systems or data when supported by the advisory.

  • DVR system commands could be executed.
  • Remote unauthenticated network access.
  • Complete compromise of the DVR.

Operational Fix

Recommended remediation, mitigation, and detection steps

These KGUARD DVR devices are likely managed by the infrastructure or network security teams responsible for maintaining device security and network access. The first practical step is to identify all affected DVRs, confirm their network exposure and business criticality, and then coordinate remediation, likely involving firmware updates or network segmentation.

  • Infrastructure or network security teams own this.
  • Verify network exposure and device criticality.
  • Plan firmware updates or network segmentation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is a KGUARD DVR?

KGUARD DVRs are digital video recorders used to capture, store, and manage video feeds from surveillance cameras. They act as dedicated hardware appliances that bridge physical security systems with local or remote network connectivity, allowing users to monitor recorded footage or live streams through digital interfaces.

How does CVE-2026-87827 work?

This vulnerability is classified as CWE-1188, which involves insecure default initialization of critical settings. In this specific case, the device firmware incorrectly exposes a system command service across all available network interfaces without requiring any authentication. Because the service is open to anyone on the network, an attacker can send unauthorized commands directly to the device's operating system, effectively taking full control.

When does this vulnerability pose a risk?

The risk occurs when the vulnerable command service is bound to public-facing network interfaces (0.0.0.0). The vulnerability does not trigger if the service is correctly restricted to the localhost interface (127.0.0.1), which is a configuration feature found in newer firmware versions released after 2017.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates a high likelihood of risk because DVRs are commonly connected directly to the internet to enable remote viewing. If your device exposes the command service on an interface reachable from the public internet, it can be accessed by remote attackers, leading to potential compromise.

What should I do if I manage these devices?

Start by identifying all KGUARD DVR units in your environment to check if they run legacy firmware from 2016 or earlier. Verify if these devices are accessible from the internet and prioritize moving them behind a firewall or using a VPN. Coordinate with your team to determine if a firmware update is available to restrict the exposed service or if the device must be isolated from the network entirely.

References