Critical Vivotek Flaw Grants Root Access (CVE-2026-22755)
ID: abf6741a-4b44-5a84-8d0c-78e8d508886b
STIX ID: report--abf6741a-4b44-5a84-8d0c-78e8d508886b
Feed Name: securityonline.info
Threat Score
Akamai SIRT disclosed CVE-2026-22755, a remote command injection in Vivotek legacy camera firmware (CVSS 9.3) where improper filename sanitization in upload_map.cgi allows unauthenticated attackers to execute arbitrary commands as root; affected models include FD8365, IB9365, and IP9165 series, creating a high risk of large-scale device compromise and botnet recruitment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
