CVE-2026-66372
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-337
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Digital Watchdog VMAX A1 G4 DVR
- Digital Watchdog VMAX IP G4 NVR
- Digital Watchdog VMAX A1 PLUS
- Digital Watchdog VA1G4 Recorder
- Digital Watchdog VG4 Recorder
Weakness type
Related vulnerabilities
- CVE-2020-28597 — A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2025-55069 — AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2022-26852 — Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unau
- CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability
- CVE-2022-40267 — Authentication Bypass Vulnerability in Web Server Function on MELSEC Series