CISA warns of stored XSS flaw in CP Plus network video recorders

Critical manufacturing and emergency services sectors using affected devices face session hijacking and data theft risks.

Illustration: CISA warns of stored XSS flaw in CP Plus network video recorders

Critical manufacturing and emergency services sectors using affected devices face session hijacking and data theft risks.

  • CISA issued advisory for stored cross-site scripting vulnerability in CP Plus 8-channel network video recorders
  • Flaw allows attackers to inject malicious scripts that execute when administrators access affected pages
  • Devices deployed across India, Nepal, UAE and Gambia in critical infrastructure sectors

The US Cybersecurity and Infrastructure Security Agency has issued an advisory warning of a stored cross-site scripting vulnerability in CP Plus 8-channel network video recorders used across critical infrastructure sectors.

The vulnerability, tracked as CVE-2026-6824, affects CP Plus CP-UNR-108F1 devices running Hardware V1.0, Web V3.2.7.128806, and System V4.001.00AT009.0.R. CISA rated the flaw with a CVSS score of 8.4, indicating high severity.

The vulnerability exists due to insufficient sanitisation of user-supplied input in specific functional modules of the 1xxx series NVR devices. Attackers can inject malicious scripts that are persistently stored on the device backend, according to CISA’s advisory.

When administrators or authenticated users access affected pages, the stored scripts execute in their browsers. This creates risk of session hijacking, unauthorised actions performed with victim privileges, and potential data theft or manipulation.

The affected devices are deployed in commercial facilities, critical manufacturing, and emergency services sectors across India, Nepal, the United Arab Emirates, and Gambia. CP Plus, headquartered in India, manufactures the surveillance equipment.

Successful exploitation allows an attacker’s malicious script to execute in any authenticated user’s browser when they access the compromised interface. This could lead to compromise of user sessions, execution of unauthorised actions, exposure or manipulation of sensitive data, and degradation of overall system integrity, CISA warned.

Why It Matters

Video surveillance systems in critical infrastructure present attractive targets for attackers seeking persistent access to monitor facilities or pivot to other network segments. The stored XSS vulnerability creates particular risk because malicious scripts persist until removed, potentially affecting multiple administrative users over time.

For CISOs managing surveillance infrastructure, this advisory highlights the need for regular security assessments of physical security systems, which are often overlooked in cybersecurity programmes despite their network connectivity and administrative access requirements.

What To Do Now

  • Update affected CP Plus devices to firmware version CP-UNR-AxxxMars_PN_15_Q_00_V1.00.14.01.T.260326 as recommended by CP Plus
  • Conduct inventory of surveillance systems to identify affected CP Plus NVR models in your environment
  • Implement network segmentation to isolate surveillance systems from critical business networks

Sources