preloader

· · digital-security iot cve botnet mirai ddos vulnerability-management network-security europe small-business

There Is No Patch for This DVR Bug, and Mirai Botnets Are Already Using It

Source: Daily CyberSecurity

A CVSS 10.0 score is rare enough that it is worth stopping on. CVE-2026-87827 earns it: no authentication, no user interaction, full remote command execution on the device it affects.

A command service left open to the entire network

KGUARD DVR and NVR units, the kind of box sitting in a back office or storeroom recording footage from shop and warehouse cameras, ship in older firmware builds with a system command execution service bound to every network interface, 0.0.0.0, rather than restricted to the device itself. A remote attacker with nothing more than network access to that service, no login, no exploit chain, no prior foothold, can run arbitrary system commands and take the device over completely. Affected models span KGUARD’s D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, and the D97xx, D98xx and D99xx families running firmware dated 2016 or earlier.

Already recruited into two active botnets

This is not a theoretical exposure. Security researchers have confirmed the flaw is being actively exploited in the wild by the Mirai_ptea variant, also tracked as Rimasuta, and by Mirai_aurora, both using it to pull vulnerable DVRs into their botnets for further malware propagation and DDoS activity. Mirai-family malware has spent a decade proving that unauthenticated remote command execution on internet-facing video recorders is one of the most reliable ways to build attack infrastructure at scale, and this bug fits that pattern exactly.

Why “update your firmware” does not fix this one

KGUARD firmware released from 2017 onward addresses the issue, but only by restricting the command service to localhost, meaning it is not exposed to the network at all in newer builds. For the affected legacy models there is no patched firmware to install: the fix is a design change that only exists in later hardware and software generations. Any organisation still running one of the affected DVR models on a 2016-era firmware image has no update path that closes the hole while keeping the device in service.

What this means if you have DVRs or NVRs on your network

Security camera recorders are exactly the kind of device that gets installed once, plugged into the network, and never looked at again until something fails. That makes them a persistent, forgotten entry point, and a DVR compromised into a botnet rarely shows any visible symptom beyond a slightly slower internet connection. If your organisation, or a retail or warehouse site you operate in Europe, runs KGUARD equipment of this vintage, the device needs to come off the open network now, either by replacing it or by isolating it behind a firewall or VLAN with no inbound access from the internet or the general office network.

If you want a European team to inventory the DVRs, NVRs and other forgotten network devices across your sites, work out which ones can no longer be safely patched, and get them properly isolated or replaced, contact Excello Digital. We help organisations find the devices nobody has thought about in years before a botnet finds them first.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!