Skip to content
Rota Nacional

Cyber ·

Critical Firmware Flaw in VIVOTEK Cameras

An alert published on September 29, 2026 says CVE-2026-22755 affects multiple VIVOTEK camera models. Command injection may enable remote execution, possibly as root; the vendor recommends installing the latest firmware.

The CISA notice, dated September 29, 2026, reports CVE-2026-22755, a command-injection flaw in firmware modules used by several VIVOTEK network camera models. The stated rating is CVSS v3 10. Exploitation may allow remote commands, possibly with root privileges, and compromise the camera system.

The notice lists equipment in the V, C, and S series, as well as Dome, Panoramic, Bullet, and other models. Examples include FD9187, FD9389, FE9180, IB9387, IP9172, FD8365, FE9381, and IB9371. Check the original notice and CSAF summary for the complete affected-device list; do not assume a model is out of scope without verifying it.

To respond, inventory the cameras and check their series, model, and firmware version. Compare those details with the official list and follow VIVOTEK’s recommendation to install the latest applicable firmware. Consult the CISA notice and CSAF summary to confirm scope and instructions; also verify details against the vendor’s official documentation before updating.

If you use AI to summarize or apply the notice, avoid submitting credentials, sensitive configurations, or personal data unless necessary. Verify technical recommendations against the official source and review any update plan before carrying it out.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free