SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-87827

CRITICAL · CVSS 10 EPSS 1.07% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Certain KGUARD DVR devices with vulnerable firmware expose an unauthenticated system command execution service on all network interfaces, allowing remote attackers to execute arbitrary commands and potentially gain complete control over the device. This critical vulnerability, which has been actively exploited by botnets such as Mirai, affects devices with firmware dating back to 2016, necessitating immediate attention from organizations using these DVRs to mitigate the risk of malware propagation and DDoS attacks. Users should prioritize updating their firmware to versions released after 2017, which restrict the vulnerable service to the localhost interface.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87827
Severity
CRITICAL
CVSS
10
EPSS
1.07%

Original NVD Description

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity. The vulnerability was reported to affect firmware dating from 2016, while firmware released after 2017 appears to mitigate the issue by restricting the affected service to the localhost interface (127.0.0.1) instead of exposing it on all interfaces (0.0.0.0). The affected-device list reported by Netlab includes many D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants and several associated hardware revisions The exploit is included in some version of rapperbot and exploited in 2026. This assignment has been made to document the active exploitation and lack of documentation from the vendor.