
🚨 #ALERT — CISA FLAGS VIVOTEK CVE-2026-22755: LEGACY CAMERA COMMAND INJECTION HAS A PUBLIC WORKING EXPLOIT AND CAN REACH ROOT September 29, 2026 DISCLOSED BY: CISA ICS / Akamai SIRT PRODUCT: VIVOTEK legacy camera firmware across dozens of older models CVE: CVE-2026-22755 IMPACT: OS command injection in `upload_map.cgi`. Akamai demonstrated that an attacker-controlled filename can reach `system()` and execute commands with the privileges of the camera's HTTP server, which ran as root in the analyzed firmware. Akamai's analysis indicates authentication is likely not required on affected devices and it developed a working exploit for validation. EXPLOITATION STATUS: PUBLIC WORKING PoC / EXPLOIT CONFIRMED NO CONFIRMED MALICIOUS IN-THE-WILD EXPLOITATION IDENTIFIED Accuracy note: The vulnerability itself was technically disclosed in January 2026. The new event is CISA's September 29 ICS advisory; it should not be labeled active exploitation without additional evidence. Forensic triage: Akamai published detection/YARA guidance for `upload_map.cgi` exploitation attempts. URGENT ACTION: These are largely legacy/EOL cameras. Do not expose them directly to the internet; isolate them on protected internal networks and apply segmentation/firewall controls. Replace devices for which supported security firmware is unavailable. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 TECHNICAL: https://www.akamai.com/blog/security-research/command-injection-vivotek-legacy-firmware-need-to-know #CyberSecurity #ThreatIntel #VIVOTEK #CameraSecurity #IoT #RCE #PoC #CVE
