CVE-2026-0629Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-06: 1Mentions · 2026-02-17: 1Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-27: 101-2802-0602-1702-27
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-061
Patch1
2026-02-171
Patch1
2026-02-271
Disclosure1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Disclosure

    TP-Link VIGI 製品群の脆弱性 CVE-2026-0629 が FIX:パスワード回復処理を介した認証バイパス https://iototsecnews.jp/2026/01/20/tp-link-router-flaw-enables-authentication-bypass-through-password-recovery-mechanism/ TP-Link のセキュリティ・カメラ VIGI シリーズにおいて、パスワードを知らなくても管理権限を奪えてしまう深刻な脆弱性が見つかりました。この問題の背景にあるのは、カメラの設定画面にある、パスワード再設定 (リカバリ) に存在する不適切なチェックによる認証バイパスの可能性です。同じ LAN 内にいる攻撃者が、ブラウザ上で動くプログラムの、認証状態を示す値 (状態変数) などを操作すると、本来は必要な本人確認をすり抜けて、管理者パスワードを勝手にリセットできてしまいます。 この脆弱性 CVE-2026-0629 を悪用されると、カメラの映像を盗み見られるだけでなく、コンフィグの変更や、ネットワーク内の他のデバイスを攻撃するための足がかりにされるリスクがあります。ご利用のチームは、ご注意ください。よろしければ、TP-Link での検索結果も、ご参照ください。 #CVE20260629 #TPLink #VIGI #Vulnerability

    Post summary

    The article announces a severe authentication bypass flaw (CVE-2026-0629) in TP‑Link VIGI cameras that allows LAN attackers to reset admin passwords through the password recovery mechanism. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    01000160
    485 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #AdminTakeover CVE-2026-0629: TP-Link VIGI Flaw Lets Attackers Reset Admin Passwords https://securityonline.info/cve-2026-0629-tp-link-vigi-flaw-lets-attackers-reset-admin-passwords/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces CVE‑2026‑0629, a TP‑Link VIGI flaw that allows attackers to reset admin passwords, and links to a detailed article for further information.

    0000043
    1.5K followersView on X
  • haeretics@略称ヘレ@haeretics
    Patch

    公開された脆弱性は「CVE-2026-0629」 隣接するネットワーク上から当該製品にアクセス可能な攻撃者によって、認証なしで管理者パスワードをリセットされ、管理者権限で製品を操作される。 TP-Link製IPカメラに不適切な認証の脆弱性 ファームウェア更新を https://ascii.jp/elem/000/004/372/4372602/

    Post summary

    A newly disclosed vulnerability (CVE-2026-0629) in TP‑Link IP cameras lets attackers reset administrator passwords without authentication and gain full control; a firmware update is available to mitigate the issue.

    0000051
    475 followersView on X
  • Kernyx64@kernyx64
    Patch

    05/02/2026 🚨 A vulnerability (CVE-2026-0629) in TP-Link VIGI Series IP Cameras allows unauthorized users to gain administrative access via an authentication bypass. Affected models include Cx45, Cx55, and Cx85 series, among others. Update firmware immediately to mitigate this risk. https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-01

    Post summary

    CISA discloses CVE-2026-0629, an authentication bypass in TP‑Link VIGI cameras that can grant admin rights, and urges users to update firmware immediately.

    0000051
    26 followersView on X

Explore more