A-Plus Video Technologies NVR Sensitive Data Exposure Vulnerability

Vulnerability

A sensitive data exposure vulnerability has been identified in certain NVR models by A-Plus Video Technologies. This vulnerability allows unauthenticated remote attackers to access the debug page and retrieve device status information. The affected models include AP-RM864P, AP-RM864, AP-RM832P, AP-RM832, AP-RM816, AP-BS416, AP-BS408, and AP-BS404, all running firmware version 2.1.0 or earlier.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive device information, potentially including status details that could be used for further attacks or exploitation.

Remediation

Users are advised to update the firmware to version 2.2.0 or later.

Added: Jan 12, 2026, 4:17 AM
Updated: Jan 12, 2026, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.