Public exploit puts 37 VIVOTEK camera models at risk

Published

A command injection flaw in VIVOTEK's network camera firmware can let an attacker run commands on the device, potentially as root, and a working proof of concept is already public. CISA's advisory, published on September 29, rates the bug, CVE-2026-22755, at the top of both scoring scales: 10.0 under CVSS v3.1 and 10.0 under CVSS v4.

The unusual part is how it surfaced. CISA says it found a public proof of concept written by a researcher publishing as indoushka and reported it to VIVOTEK itself. In other words, the exploit was out before the coordinated advisory was.

Dozens of models, many sectors

The advisory lists 37 affected camera models across VIVOTEK's V, C and S series, plus dome, bullet and panoramic units, including the FD9187, FD9389, IB9381, IP9172 and the licence plate recognition model IB93587LPR. VIVOTEK is headquartered in Taiwan and its cameras are deployed worldwide. CISA names government facilities, transportation, commercial facilities, energy, critical manufacturing and financial services as the sectors where they are used.

CISA describes the issue only as a command injection vulnerability in firmware modules shared by those models, meaning an attacker can slip their own instructions into a command the camera runs. The vector string marks it as reachable over the network with no login and no user interaction. CISA's summary warns that successful exploitation could lead to full compromise of the camera system. The advisory gives no further technical detail, and the published proof of concept is not something we will reproduce here.

Network cameras have been a recurring weak point this year, from the 14,500-camera hijacking operation uncovered in August to the camera and DVR flaws that exposed live video earlier this month. A camera that runs an attacker's commands is a device on your network that someone else controls.

Install the latest firmware, then fence the cameras off

VIVOTEK says it has addressed the issue and asks customers to download and install the latest firmware from its download centre. The advisory does not name a specific fixed firmware version per model, so check each device against the vendor's current release rather than assuming an earlier update covered it.

Until every unit is updated, CISA's standard guidance applies:

CISA says no known public exploitation targeting this vulnerability has been reported to it so far. With a CVSS 10 score, no authentication required and exploit code already circulating, that is a window rather than a reassurance, and anyone running these cameras on an exposed network should treat the update as urgent.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions