CISA says Viidure's dashcam platform keeps user records, live footage and firmware in a cloud bucket that anyone on the internet can read. Viidure did not answer CISA and plans no fix, so the advisory can only point users to the vendor's support page.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence58
CISA lists 37 VIVOTEK camera models open to CVE-2026-22755, a command injection bug that can give attackers remote command execution, potentially as root. Exploit code was public before the advisory, so the first job for owners is finding out which of their cameras are on the list.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
An attacker already on the camera's network can replay traffic into an administrative session on an unpatched Tapo C200 and reach its live video. TP-Link's fix shipped in August.
Reality
- Evidence58
- Adoption22
- Hype gap+25
- Incentives60
- Confidence52
Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.
Reality
- Evidence58
- Adoption47
- Hype gap+24
- Incentives62
- Confidence61
Pen Test Partners says the battery maker declined to fix exposed older installs and did not act when the UK regulator asked. On 9 April 2026 it entered administration.
Reality
- Evidence44
- Adoption28
- Hype gap+16
- Incentives68
- Confidence52
The NBU says NERO R-ONE cameras bought under a 30-million-euro EU-funded project are rebadged Russian hardware carrying an SMS-triggered backdoor. The contract was the vulnerability.
Reality
- Evidence55
- Adoption58
- Hype gap+8
- Incentives62
- Confidence57