The CISA notice, dated September 29, 2026, reports CVE-2026-22755, a command-injection flaw in firmware modules used by several VIVOTEK network camera models. The stated rating is CVSS v3 10. Exploitation may allow remote commands, possibly with root privileges, and compromise the camera system.
The notice lists equipment in the V, C, and S series, as well as Dome, Panoramic, Bullet, and other models. Examples include FD9187, FD9389, FE9180, IB9387, IP9172, FD8365, FE9381, and IB9371. Check the original notice and CSAF summary for the complete affected-device list; do not assume a model is out of scope without verifying it.
To respond, inventory the cameras and check their series, model, and firmware version. Compare those details with the official list and follow VIVOTEK’s recommendation to install the latest applicable firmware. Consult the CISA notice and CSAF summary to confirm scope and instructions; also verify details against the vendor’s official documentation before updating.
If you use AI to summarize or apply the notice, avoid submitting credentials, sensitive configurations, or personal data unless necessary. Verify technical recommendations against the official source and review any update plan before carrying it out.