That is correct. I used the application tool which is the http vulnerability to get the cameras password changed.
I then tried it with the NVR but it refused it.
I then tried the web paged based one linked in the first post of this thread, but I got errors 2022 and 2015 when using the serial...