Critical Vivotek Flaw Enables Remote Arbitrary Code Execution
ID: 34317d8c-e6b6-5563-b83d-53fb4540b6d2
STIX ID: report--34317d8c-e6b6-5563-b83d-53fb4540b6d2
Feed Name: GBHackers
Akamai SIRT disclosed CVE-2026-22755: an unauthenticated command injection in legacy Vivotek camera firmware that lets attackers run arbitrary commands as root by exploiting unsafe filename handling in /cgi-bin/admin/upload_map.cgi. The report provides a working proof-of-concept using crafted firmware and environment variables, lists dozens of affected models and firmware versions, supplies IOCs (endpoint, POST_FILE_NAME pattern with semicolon, firmware magic bytes) and a YARA rule, and urges immediate patching, sanitization of uploads, and network mitigations to prevent botnet recruitment and full device compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
