VIVOTEK Camera Flaw Exposes Dozens of Models to Unauthenticated Command Execution

CISA warns CVE-2026-22755 in VIVOTEK upload_map.cgi allows unauthenticated remote command execution with root privileges across dozens of camera models.

VIVOTEK Camera Flaw Exposes Dozens of Models to Unauthenticated Command Execution
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

CISA warns of a critical firmware weakness

CISA published industrial control systems advisory ICSA-26-272-03 on September 29, 2026, detailing a command-injection vulnerability affecting numerous VIVOTEK network cameras.

Tracked as CVE-2026-22755, the flaw resides in the firmware component upload_map.cgi. An unauthenticated remote attacker may be able to inject operating-system commands and execute them on a vulnerable camera, potentially with root privileges.

That level of access could allow an intruder to take full control of the device. Depending on its deployment and network position, a compromised camera could also become an entry point for attacks against connected systems.

The CVE Program classifies the issue as CWE-77: Improper Neutralization of Special Elements used in a Command (“Command Injection”). Its CVE record was published on January 13, 2026, and updated on January 20, 2026.

CISA identified deployments worldwide across government services and facilities, transportation systems, commercial facilities, energy, critical manufacturing, and financial services. VIVOTEK is headquartered in Taiwan.

The vulnerable endpoint can pass attacker input to system commands

Command injection occurs when software incorporates externally controlled data into a command without safely neutralizing characters that alter how the operating system interprets it.

In this case, the vulnerable element is upload_map.cgi, a CGI firmware module used by the affected cameras. The available technical information does not identify the exact parameter carrying malicious input or provide a complete request sequence. It also does not describe any authentication or configuration prerequisite.

The published scoring vectors indicate that an attacker can reach the vulnerable component over a network. Exploitation is assessed as low complexity, requires no existing privileges, and does not depend on user interaction.

Successful exploitation may therefore permit remote command execution directly on the camera. CISA warns that commands could run with root privileges, giving the attacker broad control over the device’s operating environment.

Possible consequences include loss of camera availability, unauthorized configuration changes, access to data handled by the device, and use of the camera to affect other systems. The scoring also reflects high confidentiality, integrity, and availability impacts extending beyond the vulnerable device itself.

CISA found a public proof of concept authored by indoushka and reported the issue to VIVOTEK. The CVE record credits Larry W. Cashdollar with discovering the vulnerability. Despite the existence of public exploit material, CISA said it had received no reports of public exploitation specifically targeting the flaw when it issued the advisory.

A broad set of camera families is affected

The affected inventory spans fixed dome, bullet, panoramic, and other VIVOTEK camera lines.

The V Series list includes:

  • FD9187, FD9189, FD9365, FD9387, FD9389, and FD9391
  • FE9191, FE9382, and FE9391
  • IB9365, IB9387, IB9389, and IB939
  • IP9165, IP9171, IP9181, and IP9191
  • IT9389, MA9321, MA9322, and MS9390

The remaining affected products are:

Product group Models
C Series FE9180
S Series IP9172, MS9321, TB9330
Dome FD8365, FD8365v2, FD9165, FD9171, FD9371, FD9381
Panoramic FE9181, FE9381
Other VIVOTEK models FE9582, IB93587LPR
Bullet IB9371, IB9381

The CVE Program record identifies 20 vulnerable firmware builds:

0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, and 0125c.

Those build numbers are not mapped to individual camera models in the published records. Administrators must therefore verify both the model and its installed firmware rather than assuming that every listed build applies uniformly across the entire product set.

The CVE record marks the product’s default status as unaffected and explicitly designates the listed builds as vulnerable. No fixed firmware build number has been disclosed.

Severity ratings differ, but every assessment is critical

The CVE Program assigns CVSS 4.0 9.3, Critical, using the following vector:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber

CISA gives the vulnerability a higher CVSS 4.0 score of 10.0, Critical:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA also reports a CVSS 3.1 score of 10.0, Critical:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

The difference stems from the scoring information retained in the respective records, not from a disagreement over whether the vulnerability is serious. All three evaluations describe a remotely reachable, unauthenticated attack with low complexity and potentially complete impact.

Public proof-of-concept availability increases the operational concern. However, a proof of concept is not equivalent to confirmed attacks, and CISA had not received reports of public exploitation specifically targeting CVE-2026-22755 when the advisory appeared.

The available information does not establish that CVE-2026-22755 has been added to CISA’s Known Exploited Vulnerabilities catalog. No KEV addition date or federal remediation deadline has been provided. It also does not identify recent VIVOTEK vulnerabilities in that catalog that could place this case within a broader pattern.

Firmware updates and network isolation are the immediate defenses

VIVOTEK has addressed the vulnerability and advises customers to install the latest firmware available for their camera through the company’s download center. Because no fixed build number is identified, administrators should confirm the appropriate release for each exact model rather than relying on a single version threshold.

Organizations should first inventory affected models and compare their installed firmware against the 20 vulnerable builds. Internet-facing cameras deserve priority because the vulnerability’s attack vector is network-accessible and does not require authentication.

CISA recommends that control-system devices remain inaccessible from the public internet. Cameras and other remote devices should be placed behind firewalls and separated from business networks to limit both direct exploitation and post-compromise movement.

Where remote administration is required, organizations should use more secure access mechanisms such as VPNs and keep the VPN software updated. A VPN does not remove the camera vulnerability, and its protection still depends partly on the security of every connected endpoint.

Before changing production environments, operators should conduct an impact analysis and risk assessment. This is particularly relevant where cameras support physical security, industrial operations, transportation, or other services in which an interruption could have operational consequences.

No vulnerability-specific indicators of compromise have been disclosed. Defenders should examine camera and network logs for unexpected access to upload_map.cgi, unexplained outbound connections, unauthorized configuration changes, abnormal processes, and signs that a device is communicating with systems outside its normal operational scope.

Suspected malicious activity should be handled through established incident-response procedures and reported to CISA for correlation and tracking. Until the correct firmware is installed, restricting access to management interfaces and isolating vulnerable cameras can reduce exposure, but those controls should not be treated as substitutes for remediation.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →