Cp Plus · Cp Plus 1Xxx Series Nvr · CVE-2026-6824
**Name of the Vulnerable Software and Affected Versions**
CP Plus 1xxx series NVR (affected versions not specified)
**Description**
A stored cross-site scripting (XSS) issue exists due to insufficient sanitization of user-supplied input in specific functional modules. This allows attackers to inject malicious scripts that are persistently stored on the device backend. When administrators or users access the affected pages, these scripts execute in their browsers, which can lead to data theft, unauthorized actions, or session hijacking (the unauthorized acquisition of a user session token to impersonate the user).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.