A stored cross-site scripting bug in CP Plus 8-channel network video recorders lets an attacker permanently embed malicious scripts on devices used across critical facilities in South Asia and the Middle East.
CVE-2026-6824 affects the CP-UNR-108F1 model's web interface, scoring 8.4 (HIGH) under CVSS 3.1. The vulnerability sits in functional modules where user-supplied input is not properly sanitized before being stored on the device backend. An attacker who can reach the interface injects a script once; every subsequent visit to the affected page by an administrator or authenticated user fires that script in their browser. The result: stolen session tokens, unauthorized commands executed at admin privilege, or direct access to footage and device configuration. Three software layers carry the flaw: hardware revision V1.0, web version 3.2.7.128806, and system version 4.001.00AT009.0.R.
NVRs and IP cameras rank among the hardest devices to keep patched. They sit at network edges, are often managed by facilities staff rather than dedicated security teams, and go unexamined for years at a stretch. The affected units are reported deployed in commercial facilities, critical manufacturing sites, and emergency services operations across India, Nepal, the UAE, and Gambia. CP Plus is India's dominant CCTV vendor, which means the actual exposure surface is considerably wider than a single-model advisory makes it look.
No active exploitation has been publicly reported. CP Plus has released a firmware update and is distributing it via a Google Drive link and a support phone line - a remediation chain that depends entirely on operators knowing the advisory exists.
