CISA flags CVSS 10.0 command-injection in 40 VIVOTEK camera models
Remote code execution with root privileges, no authentication required, this is the severity tier that triggers emergency patching windows.
TL;DR
CISA published ICSA-26-272-03 Tuesday, detailing CVE-2026-22755, a command-injection vulnerability in firmware modules used by more than 40 VIVOTEK network camera models spanning seven product series. The CVSS score is 10.0 in both v3.1 and v4.0 scoring, network-accessible, no authentication, no user interaction, full scope-change compromise. The advisory lists affected sectors as government services and facilities, transportation, commercial facilities, energy, critical manufacturing, and financial services. VIVOTEK says it has addressed the issue and directs users to its download center for updated firmware; CISA notes it discovered a public proof of concept authored by the researcher indoushka.
CISA published its advisory Tuesday after discovering a public proof of concept for CVE-2026-22755. The vulnerability is a textbook command-injection flaw (CWE-77) in firmware used across a sprawling list of VIVOTEK camera models: the V Series, C Series, S Series, Dome, Bullet, and Panoramic lines all appear in the affected-products table. The advisory lists 37 model entries, several of which cover sub-variants, pushing the total above 40.
The metrics tell the story without needing amplification. CVSS v3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That's the full house, network vector, low complexity, no privileges, no user interaction, scope changed, high impact on confidentiality, integrity, and availability. The v4.0 string mirrors it at the same 10.0 severity. When the scope flag is set to changed, the scoring model is saying the vulnerable component and the impacted component are different things, which in operational terms means compromise of the camera can reach beyond the camera.
What the advisory doesn't say is when patches ship for each model or what interim mitigations operators should deploy while waiting. VIVOTEK's remediation language is a single sentence directing users to its download center. That's thinner than what organizations running these cameras on segmented networks need, especially given the six critical-infrastructure sectors CISA flags as deployment contexts.
CISA's recommended-practices boilerplate emphasizes minimizing network exposure, isolating control-system devices behind firewalls, and using VPNs for remote access. For the federal contractors and critical-infrastructure operators running these cameras, the immediate question is whether the cameras are reachable from anything that matters. The CVSS scope flag answers that question for anyone whose segmentation isn't airtight, and surveillance-network segmentation rarely survives a candid audit.
Published ·Deep Fathom