Security1 publisher2 min readPublished
CVE-2026-22755 opens 37 VIVOTEK camera models to remote command execution
CISA lists 37 VIVOTEK camera models open to CVE-2026-22755, a command injection bug that can give attackers remote command execution, potentially as root. Exploit code was public before the advisory, so the first job for owners is finding out which of their cameras are on the list.
The Watch · Security desk

What happened
- The flaw sits in firmware modules that VIVOTEK reuses across its V, S and C Series, Dome, Panoramic and Bullet camera lines.
- CISA found the proof of concept, credited to indoushka, already public and reported it to VIVOTEK.
- CISA says the cameras are deployed worldwide in government facilities, transportation, energy, critical manufacturing, financial services and commercial facilities.
- VIVOTEK says it has addressed the issue and tells users to download and install the latest firmware from its download center.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An attacker who can route to an unpatched camera starts from published code, so most of the attacker's effort goes into finding exposed units.
- cost With 37 models across seven product lines, the first cost is an inventory: teams need the model number of every VIVOTEK camera before they know whether they are in scope.
- decision Owners of cameras that cannot take new firmware soon have to choose between cutting them off from the internet and business networks and leaving them reachable by public exploit code.
Command injection means input that reaches a shell command on the camera is not cleaned first, so an attacker can add commands of their own [3]. CISA's name for the class is "Improper Neutralization of Special Elements used in a Command" [3]. The result CISA describes is command execution on the device and full compromise of the camera system [2]. CISA qualifies the privilege level: "potentially with root privileges" [2].
How exploitable this is depends on the public proof of concept [4]. The advisory does not say whether the attack needs a login, which firmware build carries the fix, or whether anyone, named actor or not, has used the flaw against live cameras [9]. Until VIVOTEK or CISA says otherwise, I would plan as if no credentials are needed.
The scope is wide. Of the 37 models [1], 21 are V Series [2]. The rest are Dome, S Series, Panoramic, Bullet and C Series units, plus two listed only as "VIVOTEK Camera" [1]. One entry reads IB939, shorter than any other IB model number on the list [8]. An inventory matched on exact model strings could miss a unit whose full number starts with those five characters.
CISA gives these cameras the recommended practices it writes for control system devices [7]. For units that stay on old firmware, those practices are exposure controls. Keep the cameras unreachable from the internet, put them behind firewalls, isolate them from business networks, and use a VPN when remote access is required [7].
On the public record, the case has three parts: a single-vendor firmware bug, exploit code anyone can read, and a vendor fix [4][6]. The advisory does not link it to a sustained campaign [9].
What to watch
- VIVOTEK or CISA publishing fixed firmware version numbers and stating whether the attack needs authentication.
- Any report of CVE-2026-22755 being used against live cameras, or the public proof of concept turning up in scanning or botnet tooling.
- A corrected CISA model list that gives the full model number behind the IB939 entry.