CVE-2026-87827
Last modified
CVE-2026-87827 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity.
Description
Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| KGUARD | KGUARD_firmware | <= * |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-87827?
How severe is CVE-2026-87827?
How do I fix CVE-2026-87827?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87820CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticat…5.3
- CVE-2026-87821Lara Dashboard through 1.3.1 contains a server-side request …7.1
- CVE-2026-87822t-digest versions 3.1 through 3.3 fail to validate centroid …7.5
- CVE-2026-87823zstd-jni before 1.5.7-14 performs 32-bit signed bounds check…8.2
- CVE-2026-87824zstd-jni before 1.5.7-14 fails to validate the samples buffe…7.5
- CVE-2026-87825zstd-jni before 1.5.7-14 contains a use-after-free vulnerabi…7.7
- CVE-2026-8783A security vulnerability has been detected in omec-project a…4.3
- CVE-2026-8784A vulnerability was detected in npitre cramfs-tools up to 2.…4.2
- CVE-2026-8785A flaw has been found in projectworlds hospital-management-s…7.3
- CVE-2026-87853A flaw was found in SSSD's IdP authentication provider. The …7.5
- CVE-2026-8786A vulnerability has been found in Tencent WeKnora up to 0.3.…6.3
- CVE-2026-8787The Firebase Support & Chat Management plugin for WordPress …8.8
Are you affected by CVE-2026-87827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
