logo

Critical Vivotek Flaw Grants Root Access (CVE-2026-22755)

ID: abf6741a-4b44-5a84-8d0c-78e8d508886b

STIX ID: report--abf6741a-4b44-5a84-8d0c-78e8d508886b

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Akamai SIRT disclosed CVE-2026-22755, a remote command injection in Vivotek legacy camera firmware (CVSS 9.3) where improper filename sanitization in upload_map.cgi allows unauthenticated attackers to execute arbitrary commands as root; affected models include FD8365, IB9365, and IP9165 series, creating a high risk of large-scale device compromise and botnet recruitment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.