The geographic distribution of Bot source IPs
TL;DR
A KGUARD DVR vulnerability now tracked as CVE-2026-87827 carries a maximum CVSS score of 10.0. It lets an unauthenticated attacker run commands and fully take over the device. Mirai botnets have already exploited it in the wild.
- CVE: CVE-2026-87827
- CVSS: 10 (Critical · CVSSv4)
- Product: KGUARD_firmware
- Impact: KGUARD DVR unauthenticated remote command execution vulnerability
- Status: No confirmed exploitation yet
- EPSS: 1.1% (30-day)
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy this KGUARD DVR vulnerability matters
Digital video recorders sit on many home and business networks. A full takeover turns them into attack tools. This KGUARD DVR vulnerability gives attackers exactly that power.
Netlab 360 first flagged the flaw during botnet tracking. Per its advisory, a remote attacker can run commands “potentially resulting in complete compromise of the DVR.” The score of 10.0 reflects that worst-case impact.
How the attack works
One program on the KGUARD firmware listens on a network port. Crucially, it binds to 0.0.0.0 and needs no authentication. As Netlab explains, that service can “remotely execute system commands without authentication.”
A remote, unauthenticated attacker reaches the service over the network. From there, the attacker runs arbitrary system commands. That access leads to full control of the device. Netlab has withheld the exact port to limit further abuse.
Exploited in the wild by Mirai
This is not a theoretical risk. The Mirai_ptea (Rimasuta) and Mirai_aurora botnets both weaponized the flaw. They used it for malware spread and later DDoS attacks. The exploit was later added to some RapperBot versions and abused again in 2026.
Affected versions
The flaw affects KGUARD DVR firmware dating from 2016. Firmware released after 2017 mitigates it by binding the service to 127.0.0.1 instead. Netlab estimated at least 3,000 exposed devices still online. Affected models span many D1004NR, D1008NR, D1016NR, D1104, D1108NR, D1116NR, and D99xx variants.
Patch and mitigation steps
Update to firmware released after 2017 where possible. If no update exists, remove the DVR from direct internet exposure. Place it behind a firewall and block inbound access to its management port. Additionally, segment DVRs away from critical systems. Finally, watch for unusual outbound traffic that may signal botnet activity.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!