CISA Warns of Critical Command Injection Vulnerability in VIVOTEK Camera Firmware
CISA has issued a critical alert regarding a command injection vulnerability (CVE-2026-22755) affecting numerous VIVOTEK camera firmware models, enabling remote system compromise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory detailing a severe command injection vulnerability, identified as CVE-2026-22755, that impacts a wide array of VIVOTEK camera firmware models. Successful exploitation of this flaw allows remote attackers to execute arbitrary commands on affected devices, potentially with root privileges, leading to a complete compromise of the camera system.
The vulnerability stems from improper neutralization of special elements used in commands, a common weakness categorized under CWE-77. This means that specially crafted inputs can be interpreted as system commands by the vulnerable firmware, granting attackers unauthorized control. The potential for root-level access is particularly concerning, as it provides attackers with the highest level of privilege on the device, enabling them to manipulate settings, access sensitive data, or use the compromised camera as a pivot point into other networks.
A broad range of VIVOTEK camera models across its V, C, S, Dome, and Panoramic series are affected. The advisory lists specific model numbers, including but not limited to FD9187, FD9189, FD9365, FD9387, FE9180, and IB9365, among many others. The widespread impact across numerous product lines suggests a significant number of devices globally could be at risk, potentially affecting critical infrastructure sectors such as government services, transportation, commercial facilities, energy, manufacturing, and financial services.
The CVSS v3.1 score for this vulnerability is a critical 10.0, indicating the highest level of severity. The CVSS v4.0 score also reflects a critical severity. These scores are based on factors such as network accessibility (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction needed (UI:N), and a significant impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The critical nature of this vulnerability underscores the urgent need for users to take immediate action.
VIVOTEK has acknowledged the vulnerability and has released updated firmware to address the issue. The company strongly encourages all users of affected camera models to download and install the latest firmware versions as soon as possible. Information on where to obtain the updated firmware can be found on VIVOTEK's official download center. Organizations are advised to consult the VIVOTEK website for specific instructions related to their camera models.
CISA has also provided recommended practices for mitigating the risks associated with such vulnerabilities. These include minimizing network exposure of control system devices, ensuring they are located behind firewalls, and isolating them from business networks. When remote access is necessary, using secure methods like VPNs is advised, with the caveat that VPNs themselves must be kept updated. Organizations are urged to perform thorough impact analyses and risk assessments before implementing any defensive measures.
This advisory was prompted by the discovery of a public proof of concept (PoC) by researcher indoushka, who subsequently reported the vulnerability to VIVOTEK. The existence of a public PoC significantly increases the risk of exploitation, as it lowers the barrier for attackers to develop and deploy malicious tools targeting vulnerable systems.
Given the critical severity and the wide range of affected devices, VIVOTEK camera users should prioritize updating their firmware. Failure to do so could expose sensitive surveillance data, allow for unauthorized system access, and potentially lead to broader network compromises. CISA continues to monitor the threat landscape and encourages organizations to report any suspected malicious activity.