Critical TP-Link VIGI camera flaw allowed remote takeover of surveillance systems
ID: 6b206fec-1c41-53ab-be5f-22b414800584
STIX ID: report--6b206fec-1c41-53ab-be5f-22b414800584
Feed Name: Security Affairs
Threat Score
TP-Link patched a critical authentication-bypass vulnerability (CVE-2026-0629, CVSS 8.7) in over 32 VIGI C and VIGI InSight camera models that allowed attackers on the local network to abuse the password recovery feature, reset the admin password without verification, and gain full control; researcher Arko Dhar found more than 2,500 internet-exposed vulnerable cameras, raising risks of spying, network intrusion, botnets, evidence tampering, and regulatory exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
