VORANT. Threat Intelligence Research Sign in Create a free account

VIVOTEK Cameras Vulnerable to Root RCE Flaw

elevated vulnerability government-nationaltransportationenergymanufacturingfinancial-services

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

A command injection flaw (CVE-2026-22755) affects dozens of VIVOTEK network camera models, allowing remote command execution with root privileges; a public PoC exists but no in-the-wild exploitation reported.

CISA has published an ICS advisory for a command injection vulnerability (CVE-2026-22755, CWE-77) impacting firmware across more than 35 VIVOTEK network camera models spanning the V, C, S, Dome, Panoramic, and Bullet series. Successful exploitation could allow an attacker to achieve remote command execution, potentially with root privileges, resulting in full compromise of the affected camera. VIVOTEK is a Taiwan-headquartered manufacturer with devices deployed worldwide across critical infrastructure sectors including government facilities, transportation, commercial facilities, energy, critical manufacturing, and financial services.

CISA discovered a public proof-of-concept for this vulnerability, authored by a researcher known as 'indoushka', and reported it to VIVOTEK. As of the advisory's release, no known public exploitation specifically targeting this vulnerability has been reported to CISA. VIVOTEK has released updated firmware addressing the issue and recommends all users update to the latest available version via its official download center.

Defenders operating any of the listed VIVOTEK camera models should prioritize firmware updates and, in the interim, apply standard ICS network hardening: minimize internet exposure of camera management interfaces, place devices behind firewalls and segment them from business networks, and use VPNs with up-to-date patching for any required remote access. Given the existence of a public PoC and the potential for root-level compromise, organizations should treat unpatched exposed devices as a priority remediation item despite the absence of confirmed active exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-22755

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,331 reports from 152 sources, 2,732 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs