VIVOTEK Camera Firmware

Cybersecurity and Infrastructure Security Agency CISA ·

VIVOTEK Camera Firmware khardwood Sep 29, 2026 Release Date September 29, 2026 Description View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series model_FD9387 (CVE-2026-22755) V Series model_FD9389 (CVE-2026-22755) V Series model_FD9391 (CVE-2026-22755) C Series model_FE9180 (CVE-2026-22755) V Series model_FE9191 (CVE-2026-22755) V Series model_FE9382 (CVE-2026-22755) V Series model_FE9391 (CVE-2026-22755) V Series model_IB9365 (CVE-2026-22755) V Series model_IB9387 (CVE-2026-22755) V Series model_IB9389 (CVE-2026-22755) V Series model_IB939 (CVE-2026-22755) V Series model_IP9165 (CVE-2026-22755) V Series model_IP9171 (CVE-2026-22755) S Series model_IP9172 (CVE-2026-22755) V Series model_IP9181 (CVE-2026-22755) V Series model_IP9191 (CVE-2026-22755) V Series model_IT9389 (CVE-2026-22755) V Series model_MA9321 (CVE-2026-22755) V Series model_MA9322 (CVE-2026-22755) S Series model_MS9321 (CVE-2026-22755) V Series model_MS9390 (CVE-2026-22755) S Series model_TB9330 (CVE-2026-22755) Dome model_FD8365 (CVE-2026-22755) Dome model_FD8365v2 (CVE-2026-22755) Dome model_FD9165 (CVE-2026-22755) Dome model_FD9171 (CVE-2026-22755) Dome model_FD9371 (CVE-2026-22755) Dome model_FD9381 (CVE-2026-22755) Panoramic model_FE9181 (CVE-2026-22755) Panoramic model_FE9381 (CVE-2026-22755) VIVOTEK Camera model_FE9582 (CVE-2026-22755) VIVOTEK Camera model_IB93587LPR (CVE-2026-22755) Bullet model_IB9371 (CVE-2026-22755) Bullet model_IB9381 (CVE-2026-22755) CVSS Vendor Equipment Vulnerabilities v3 10 VIVOTEK VIVOTEK Camera Firmware Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Government Services and Facilities, Transportation Systems, Commercial Facilities, Energy, Critical Manufacturing, Financial Services Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-22755 A command injection vulnerability has been identified in firmware modules used by multiple network camera models from VIVOTEK. View CVE Details Affected Products VIVOTEK Camera Firmware Vendor: VIVOTEK Product Version: VIVOTEK V Series: model_FD9187, VIVOTEK V Series: model_FD9189, VIVOTEK V Series: model_FD9365, VIVOTEK V Series: model_FD9387, VIVOTEK V Series: model_FD9389, VIVOTEK V Series: model_FD9391, VIVOTEK C Series: model_FE9180, VIVOTEK V Series: model_FE9191, VIVOTEK V Series: model_FE9382, VIVOTEK V Series: model_FE9391, VIVOTEK V Series: model_IB9365, VIVOTEK V Series: model_IB9387, VIVOTEK V Series: model_IB9389, VIVOTEK V Series: model_IB939, VIVOTEK V Series: model_IP9165, VIVOTEK V Series: model_IP9171, VIVOTEK S Series: model_IP9172, VIVOTEK V Series: model_IP9181, VIVOTEK V Series: model_IP9191, VIVOTEK V Series: model_IT9389, VIVOTEK V Series: model_MA9321, VIVOTEK V Series: model_MA9322, VIVOTEK S Series: model_MS9321, VIVOTEK V Series: model_MS9390, VIVOTEK S Series: model_TB9330, VIVOTEK Dome: model_FD8365, VIVOTEK Dome: model_FD8365v2, VIVOTEK Dome: model_FD9165, VIVOTEK Dome: model_FD9171, VIVOTEK Dome: model_FD9371, VIVOTEK Dome: model_FD9381, VIVOTEK Panoramic: model_FE9181, VIVOTEK Panoramic: model_FE9381, VIVOTEK VIVOTEK Camera: model_FE9582, VIVOTEK VIVOTEK Camera: model_IB93587LPR, VIVOTEK Bullet: model_IB9371, VIVOTEK Bullet: model_IB9381 Product Status: known_affected Remediations Mitigation VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available. https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments CISA discovered a public proof of concept as authored by indoushka and reported it to VIVOTEK. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use Advisory Type ICS Advisory Topics Industrial Control System Vulnerabilities , Industrial Control Systems Alert Code ICSA-26-272-03 Sector Commercial Facilities Sector , Critical Manufacturing Sector , Energy Sector , Financial Services Sector , Government Services and Facilities Sector , Transportation Systems Sector Show 'Key Takeaways' block Off On

VIVOTEK Camera Firmware khardwood Sep 29, 2026 Release Date September 29, 2026 Description View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V Series model_FD9387 (CVE-2026-22755) V Series model_FD9389 (CVE-2026-22755) V Series model_FD9391 (CVE-2026-22755) C Series model_FE9180 (CVE-2026-22755) V Series model_FE9191 (CVE-2026-22755) V Series model_FE9382 (CVE-2026-22755) V Series model_FE9391 (CVE-2026-22755) V Series model_IB9365 (CVE-2026-22755) V Series model_IB9387 (CVE-2026-22755) V Series model_IB9389 (CVE-2026-22755) V Series model_IB939 (CVE-2026-22755) V Series model_IP9165 (CVE-2026-22755) V Series model_IP9171 (CVE-2026-22755) S Series model_IP9172 (CVE-2026-22755) V Series model_IP9181 (CVE-2026-22755) V Series model_IP9191 (CVE-2026-22755) V Series model_IT9389 (CVE-2026-22755) V Series model_MA9321 (CVE-2026-22755) V Series model_MA9322 (CVE-2026-22755) S Series model_MS9321 (CVE-2026-22755) V Series model_MS9390 (CVE-2026-22755) S Series model_TB9330 (CVE-2026-22755) Dome model_FD8365 (CVE-2026-22755) Dome model_FD8365v2 (CVE-2026-22755) Dome model_FD9165 (CVE-2026-22755) Dome model_FD9171 (CVE-2026-22755) Dome model_FD9371 (CVE-2026-22755) Dome model_FD9381 (CVE-2026-22755) Panoramic model_FE9181 (CVE-2026-22755) Panoramic model_FE9381 (CVE-2026-22755) VIVOTEK Camera model_FE9582 (CVE-2026-22755) VIVOTEK Camera model_IB93587LPR (CVE-2026-22755) Bullet model_IB9371 (CVE-2026-22755) Bullet model_IB9381 (CVE-2026-22755) CVSS Vendor Equipment Vulnerabilities v3 10 VIVOTEK VIVOTEK Camera Firmware Improper Neutralization of Special Elements used in a Command ('Command Injection') Background Critical Infrastructure Sectors: Government Services and Facilities, Transportation Systems, Commercial Facilities, Energy, Critical Manufacturing, Financial Services Countries/Areas Deployed: Worldwide Company Headquarters Location: Taiwan Vulnerabilities Expand All + CVE-2026-22755 A command injection vulnerability has been identified in firmware modules used by multiple network camera models from VIVOTEK. View CVE Details Affected Products VIVOTEK Camera Firmware Vendor: VIVOTEK Product Version: VIVOTEK V Series: model_FD9187, VIVOTEK V Series: model_FD9189, VIVOTEK V Series: model_FD9365, VIVOTEK V Series: model_FD9387, VIVOTEK V Series: model_FD9389, VIVOTEK V Series: model_FD9391, VIVOTEK C Series: model_FE9180, VIVOTEK V Series: model_FE9191, VIVOTEK V Series: model_FE9382, VIVOTEK V Series: model_FE9391, VIVOTEK V Series: model_IB9365, VIVOTEK V Series: model_IB9387, VIVOTEK V Series: model_IB9389, VIVOTEK V Series: model_IB939, VIVOTEK V Series: model_IP9165, VIVOTEK V Series: model_IP9171, VIVOTEK S Series: model_IP9172, VIVOTEK V Series: model_IP9181, VIVOTEK V Series: model_IP9191, VIVOTEK V Series: model_IT9389, VIVOTEK V Series: model_MA9321, VIVOTEK V Series: model_MA9322, VIVOTEK S Series: model_MS9321, VIVOTEK V Series: model_MS9390, VIVOTEK S Series: model_TB9330, VIVOTEK Dome: model_FD8365, VIVOTEK Dome: model_FD8365v2, VIVOTEK Dome: model_FD9165, VIVOTEK Dome: model_FD9171, VIVOTEK Dome: model_FD9371, VIVOTEK Dome: model_FD9381, VIVOTEK Panoramic: model_FE9181, VIVOTEK Panoramic: model_FE9381, VIVOTEK VIVOTEK Camera: model_FE9582, VIVOTEK VIVOTEK Camera: model_IB93587LPR, VIVOTEK Bullet: model_IB9371, VIVOTEK Bullet: model_IB9381 Product Status: known_affected Remediations Mitigation VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available. https://www.vivotek.com/en-US/resource/download-center/software-app-vadp-package Relevant CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments CISA discovered a public proof of concept as authored by indoushka and reported it to VIVOTEK. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-29 Date Revision Summary 2026-09-29 1 Initial Publication Legal Notice and Terms of Use Advisory Type ICS Advisory Topics Industrial Control System Vulnerabilities , Industrial Control Systems Alert Code ICSA-26-272-03 Sector Commercial Facilities Sector , Critical Manufacturing Sector , Energy Sector , Financial Services Sector , Government Services and Facilities Sector , Transportation Systems Sector Show 'Key Takeaways' block Off On

Источник: Cybersecurity and Infrastructure Security Agency CISA