CVE-2026-22755

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets2 URLs
Full discourse1 post
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — CISA FLAGS VIVOTEK CVE-2026-22755: LEGACY CAMERA COMMAND INJECTION HAS A PUBLIC WORKING EXPLOIT AND CAN REACH ROOT September 29, 2026 DISCLOSED BY: CISA ICS / Akamai SIRT PRODUCT: VIVOTEK legacy camera firmware across dozens of older models CVE: CVE-2026-22755 IMPACT: OS command injection in `upload_map.cgi`. Akamai demonstrated that an attacker-controlled filename can reach `system()` and execute commands with the privileges of the camera's HTTP server, which ran as root in the analyzed firmware. Akamai's analysis indicates authentication is likely not required on affected devices and it developed a working exploit for validation. EXPLOITATION STATUS: PUBLIC WORKING PoC / EXPLOIT CONFIRMED NO CONFIRMED MALICIOUS IN-THE-WILD EXPLOITATION IDENTIFIED Accuracy note: The vulnerability itself was technically disclosed in January 2026. The new event is CISA's September 29 ICS advisory; it should not be labeled active exploitation without additional evidence. Forensic triage: Akamai published detection/YARA guidance for `upload_map.cgi` exploitation attempts. URGENT ACTION: These are largely legacy/EOL cameras. Do not expose them directly to the internet; isolate them on protected internal networks and apply segmentation/firewall controls. Replace devices for which supported security firmware is unavailable. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03 TECHNICAL: https://www.akamai.com/blog/security-research/command-injection-vivotek-legacy-firmware-need-to-know #CyberSecurity #ThreatIntel #VIVOTEK #CameraSecurity #IoT #RCE #PoC #CVE

    0000077
    225 followersView on X

Explore more