---
title: Critical Unauthenticated Command Injection in Legacy VIVOTEK Network Camera Firmware
description: On September 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published an industrial control systems advisory for a critical command injection vulnerability in firmware modules shared across 37 VIVOTEK network camera models.
---

[Skip to content](https://1898advisories.burnsmcd.com/critical-unauthenticated-command-injection-in-legacy-vivotek-network-camera-firmware#main-content)

![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact us](https://1898andco.burnsmcd.com/contact-us)

[Contact us](https://1898andco.burnsmcd.com/contact-us)

 October 5, 2026

# Critical Unauthenticated Command Injection in Legacy VIVOTEK Network Camera Firmware

![Picture of The 1898 & Co. Team](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898%20Cyberthreat%20Advisory%20Blog%20Assets/1898-Co-Ampersand.png?width=50&name=1898-Co-Ampersand.png) [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team)

#### Security Advisory Brief

On September 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published an industrial control systems advisory for a critical command injection vulnerability in firmware modules shared across 37 VIVOTEK network camera models. The flaw, tracked as CVE-2026-22755 with a CVSS v3.1 score of 10.0, was first published to the CVE program on January 13, 2026, and affects legacy firmware versions 0100a through 0125c on models spanning the VIVOTEK V Series, S Series, C Series, Dome, Bullet and Panoramic product lines. VIVOTEK is headquartered in Taiwan and its cameras are deployed worldwide.

CVE-2026-22755 is an improper neutralization of special elements used in a command (CWE-77) in a file-upload handler within the camera's web interface. Improperly validated input reaches an operating system command, allowing a remote attacker to execute commands on the camera with root privileges. Because many legacy VIVOTEK cameras operate with no administrator password set, and a related flaw (CVE-2025-12592, CVSS v4.0 score of 9.3) documents default credentials on legacy VIVOTEK firmware, the vulnerability is effectively exploitable without authentication on a large share of deployed devices.

The risk is elevated because a public proof-of-concept exploit exists: CISA identified published exploit code and reported it to VIVOTEK, and the CVE Numbering Authority's CVSS v4.0 score reflects that exploit maturity. CISA has not received reports of exploitation in the wild, and as of October 2, 2026 the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Legacy network cameras are frequently internet-exposed, rarely monitored by endpoint security tooling and seldom patched, which has historically made them a preferred target for botnet operators and a durable foothold for intrusion into adjacent networks.

#### Threats and Vulnerabilities

CVE-2026-22755, with a CVSS v3.1 score of 10.0 (Critical) assigned by CISA and a CVSS v4.0 score of 9.3 (Critical) assigned by the CVE Numbering Authority, is a command injection vulnerability in a file-upload handler in legacy VIVOTEK camera firmware. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) describes a network-reachable, low-complexity attack requiring no privileges or user interaction, with impact extending beyond the camera itself; the CVSS v4.0 score of 9.3 incorporates the existence of a public proof of concept. Successful exploitation yields root-level command execution and full compromise of the camera, which an attacker can use to disable or falsify surveillance video, harvest stored credentials and configuration, enlist the device in a botnet, or pivot into the network segment where it resides. The affected models are the FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391, FE9180, FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB9371, IB9381, IB9387, IB9389, IB939, IB93587LPR, IP9165, IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390 and TB9330, running firmware versions 0100a, 0106a, 0106b, 0107a, 0107b\_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d\_48573\_1, 0122e, 0124d\_48573\_1, 012501, 012502 or 0125c. CISA reports that VIVOTEK has addressed the issue and recommends installing the latest available firmware; because these are legacy product lines, some models may have no newer firmware available and should be planned for replacement.

CVE-2025-12592, with a CVSS v4.0 score of 9.3 (Critical) and no published CVSS v3.1 score, documents that legacy VIVOTEK device firmware uses default credentials for the root and user login accounts. It was published on November 19, 2025. Its relevance to this advisory is direct: cameras that retain default or empty administrative credentials remove the only barrier between a network-reachable attacker and the vulnerable upload handler, so the two issues should be remediated together. Organizations should treat any legacy VIVOTEK camera still using factory credentials as exposed to both vulnerabilities.

#### Client Impact

Operationally, VIVOTEK cameras are commonly installed for physical security monitoring at substations, generation facilities, pipelines, manufacturing floors, transportation hubs, government buildings and commercial sites, and CISA lists Energy, Critical Manufacturing, Transportation Systems, Government Services and Facilities, Commercial Facilities and Financial Services as affected sectors. An attacker with root access to a camera can blind or manipulate surveillance feeds during a physical intrusion, use the device to generate denial-of-service traffic, or move laterally from a camera network into adjacent systems. Where cameras share a flat network with operational technology, or are reachable from video management servers that also connect to the corporate domain, a single compromised camera can become a staging point that conventional endpoint tooling will not observe.

From a compliance perspective, NERC CIP registered entities should determine whether affected cameras are part of a Physical Access Control System or support Physical Security Perimeter monitoring for medium- or high-impact BES Cyber Systems, because a compromised camera can undermine the monitoring required under CIP-006, and such systems fall within the patch and vulnerability assessment obligations of CIP-007 and CIP-010. Facilities aligned to IEC 62443 should treat unpatched, network-reachable cameras as a zone and conduit integrity issue. End-of-life cameras that can no longer receive firmware create an enduring compliance exception that must be documented with compensating controls or retired, and a compromise of surveillance infrastructure can carry regulatory and reputational consequences beyond the cost of remediation.

#### Mitigations

Organizations operating VIVOTEK network cameras should take the following actions to reduce exposure to CVE-2026-22755 and CVE-2025-12592:

1. Inventory every VIVOTEK camera, matching model numbers and firmware versions against the 37 affected models and the 0100a through 0125c firmware range, and record each camera's network location, management path and credential status.
2. Install the latest firmware available from VIVOTEK for each affected model, prioritizing internet-facing cameras and those at critical facilities or reachable from operational technology networks; where no newer firmware exists for a model, plan and fund its replacement.
3. Set a strong, unique administrator password on every camera and disable or change any default root and user accounts, which closes the unauthenticated path on devices that currently have no password set.
4. Remove camera web and streaming interfaces from direct internet exposure, place cameras on a dedicated firewalled VLAN, and restrict access to camera administrative web interfaces to the video management servers and administrative hosts that require it.
5. Restrict outbound traffic from camera networks to the destinations required for video management, time synchronization and approved firmware updates, alert on any camera-initiated connection to the internet or to user, server or OT segments, and review camera logs and network flows for signs of prior compromise before and after remediation.

Applying vendor firmware where available, replacing devices that can no longer be updated, and enforcing credential, segmentation and egress controls together offer the most effective path to reducing the likelihood that a publicly available exploit results in a camera compromise or a pivot into critical networks.

#### 1898 & Co. Response

1898 & Co. supports critical infrastructure organizations in identifying and assessing physical security and operational technology devices such as network cameras, including asset inventory, firmware and vulnerability assessment, and review of how these devices connect to control system and corporate networks. Our team has worked with utilities, manufacturers and public-sector organizations to locate internet-exposed and unmanaged devices and to prioritize remediation and replacement based on operational consequence.

Our threat hunting and incident response practitioners can help clients search for indicators of exploitation and post-exploitation activity on camera networks, including unexpected access to camera administrative interfaces, camera-initiated connections and lateral movement from video segments. Where evidence of compromise is found, 1898 & Co. can support containment, forensic analysis and recovery planning coordinated with the client's operations and physical security teams.

1898 & Co. also assists clients with the longer-term architecture and governance work that reduces exposure to device-level vulnerabilities, including network segmentation and zone and conduit design aligned with IEC 62443, NERC CIP compliance support, and lifecycle and patch management programs for embedded and IoT devices. Organizations seeking help evaluating their exposure to CVE-2026-22755 or planning the retirement of legacy surveillance equipment are encouraged to contact 1898 & Co.

#### Sources

1. [CISA ICS Advisory ICSA-26-272-03 — VIVOTEK Camera Firmware](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03)
2. [NVD Entry — CVE-2026-22755](https://nvd.nist.gov/vuln/detail/CVE-2026-22755)
3. [NVD Entry — CVE-2025-12592](https://nvd.nist.gov/vuln/detail/CVE-2025-12592)
4. [MITRE CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection')](https://cwe.mitre.org/data/definitions/77.html)
5. [VIVOTEK Download Center (vendor remediation link cited by CISA)](https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package)
6. [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
7. [CISA — Industrial Control Systems Recommended Practices](https://www.cisa.gov/resources-tools/resources/ics-recommended-practices)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team",
    "url" : "https://1898advisories.burnsmcd.com/author/1898-co-team"
  },
  "dateModified" : "2026-10-05T21:42:52.834Z",
  "datePublished" : "2026-10-05T21:42:52.000Z",
  "headline" : "Critical Unauthenticated Command Injection in Legacy VIVOTEK Network Camera Firmware",
  "mainEntityOfPage" : {
    "@id" : "https://1898advisories.burnsmcd.com/critical-unauthenticated-command-injection-in-legacy-vivotek-network-camera-firmware",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//cdn2.hubspot.net/hub/477837/file-2585615236-jpg/Logo_1_Primary_2Color1.jpg"
    },
    "name" : "Burns & McDonnell Engineering Co"
  }
}
```