# VIVOTEK Cameras Vulnerable to Root RCE Flaw

Published: 2026-09-29 · Severity: elevated · Sectors: government-national, transportation, energy, manufacturing, financial-services
Canonical: https://vorant.io/reports/6257acd9-22ef-5a41-97ab-8b2ff075f5b7/vivotek-cameras-vulnerable-to-root-rce-flaw

> A command injection flaw (CVE-2026-22755) affects dozens of VIVOTEK network camera models, allowing remote command execution with root privileges; a public PoC exists but no in-the-wild exploitation reported.

CISA has published an ICS advisory for a command injection vulnerability (CVE-2026-22755, CWE-77) impacting firmware across more than 35 VIVOTEK network camera models spanning the V, C, S, Dome, Panoramic, and Bullet series. Successful exploitation could allow an attacker to achieve remote command execution, potentially with root privileges, resulting in full compromise of the affected camera. VIVOTEK is a Taiwan-headquartered manufacturer with devices deployed worldwide across critical infrastructure sectors including government facilities, transportation, commercial facilities, energy, critical manufacturing, and financial services.

CISA discovered a public proof-of-concept for this vulnerability, authored by a researcher known as 'indoushka', and reported it to VIVOTEK. As of the advisory's release, no known public exploitation specifically targeting this vulnerability has been reported to CISA. VIVOTEK has released updated firmware addressing the issue and recommends all users update to the latest available version via its official download center.

Defenders operating any of the listed VIVOTEK camera models should prioritize firmware updates and, in the interim, apply standard ICS network hardening: minimize internet exposure of camera management interfaces, place devices behind firewalls and segment them from business networks, and use VPNs with up-to-date patching for any required remote access. Given the existence of a public PoC and the potential for root-level compromise, organizations should treat unpatched exposed devices as a priority remediation item despite the absence of confirmed active exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-22755

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6257acd9-22ef-5a41-97ab-8b2ff075f5b7/vivotek-cameras-vulnerable-to-root-rce-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
