Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Command Execution in VIVOTEK Camera Firmware (CVE‑2026‑22755) Threatens Physical Security Systems

VIVOTEK disclosed CVE‑2026‑22755, a remote‑code‑execution flaw affecting dozens of IP‑camera models. Exploitation grants unauthenticated root access, putting physical‑security deployments at risk. The issue underscores the importance of continuous firmware monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Remote Command Execution in VIVOTEK Camera Firmware (CVE‑2026‑22755) Threatens Physical Security Systems

What It Is — VIVOTEK disclosed a critical remote‑code‑execution (RCE) flaw (CVE‑2026‑22755) in the firmware of dozens of its V, C, S, and Dome series IP cameras. Successful exploitation grants an attacker unauthenticated command execution with root privileges, enabling full takeover of the camera system.

Exploitability — Public advisory; proof‑of‑concept code has been observed in the wild. The vulnerability is rated high severity (CVSS ≈ 8.8) and can be triggered over the network without authentication.

Affected Products — All listed VIVOTEK models in the advisory, including V Series FD9187, FD9189, FD9365, FD9387, FD9389, FD9391; C Series FE9180; S Series IP9172, MS9321, TB9330; Dome series FD8365, FD8365v2, FD9165, FD9171, FD9371, etc.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous firmware integrity monitoring as evidence of a defensible security posture.
  • Highlights a gap in configuration and patch‑management controls that span multiple compliance frameworks.
  • Enterprise buyers increasingly demand proof that IoT/OT devices are kept up‑to‑date, otherwise the overall trust signal for a site is weakened.

Recommended Actions

  • Inventory all VIVOTEK cameras and verify firmware versions against the vendor’s patch list.
  • Apply the latest firmware updates immediately; enable automatic update mechanisms where available.
  • Integrate camera firmware status into a continuous monitoring platform to generate audit‑ready evidence of compliance.
  • Review network segmentation and least‑privilege access controls for camera management interfaces.

Source: CISA Advisory – ICSA‑26‑272‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →