IM
IronMonkey Threat Research
‹ Back to ICS Advisories

VIVOTEK Camera Firmware

CRITICAL
CVSS 10.0
Date 2026-09-29T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-22755 10.0 critical
A command injection vulnerability has been identified in firmware modules used by multiple network camera models from VIVOTEK.

// Remediations (1)

Mitigation: VIVOTEK has addressed this issue and encourages users to download and install the latest firmware av
VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available.https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package

// References