logo

Critical TP-Link VIGI camera flaw allowed remote takeover of surveillance systems

ID: 6b206fec-1c41-53ab-be5f-22b414800584

STIX ID: report--6b206fec-1c41-53ab-be5f-22b414800584

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

TP-Link patched a critical authentication-bypass vulnerability (CVE-2026-0629, CVSS 8.7) in over 32 VIGI C and VIGI InSight camera models that allowed attackers on the local network to abuse the password recovery feature, reset the admin password without verification, and gain full control; researcher Arko Dhar found more than 2,500 internet-exposed vulnerable cameras, raising risks of spying, network intrusion, botnets, evidence tampering, and regulatory exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.