ZeroHour

CVE-2026-22755

large

OS Command Injection in Vivotek 9-Series IP Camera Firmware

CVSS 4.0
9.3 critical
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2026-22755 is an OS command injection flaw (CWE-77, improper neutralization of special elements used in a command) in the firmware of 36 Vivotek network camera models spanning the FD, FE, IB, IP, IT, MA, MS and TB 9-series lines. Per the CVSS 4.0 vector, it is exploitable over the network with no privileges required and no user interaction, meaning an attacker can send crafted input to a network-facing service in the camera firmware and have arbitrary operating-system commands executed on the device. Successful exploitation carries high impact to the camera's confidentiality, integrity and availability - and to subsequent systems - consistent with full device compromise and potential lateral movement into the surrounding surveillance network. Any deployment running one of the listed models on one of the 20 listed firmware module versions (0100a through 0125c) is affected, with directly internet-exposed cameras at greatest risk. No public proof of concept or confirmed in-the-wild exploitation is known (not yet in CISA KEV), but EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile), making this a high-priority patching target.

What to do: Inventory all Vivotek cameras and compare installed firmware module versions against the affected list (0100a through 0125c on the listed models); upgrade to Vivotek's patched firmware as soon as a fixed release is identified, since the advisory data specifies no fixed version. Until patched, avoid exposing affected cameras' web interfaces directly to the internet - restrict management access to isolated VLANs or VPN - and monitor devices for exploitation attempts, prioritizing internet-facing units given the 20.7% EPSS (97th percentile).

Affected
Vivotek FD-series models: FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek FE-series models: FE9180, FE9181, FE9191, FE9381, FE9382, FE9391, FE9582firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek IB-series models: IB9365, IB93587LPR, IB9371, IB9381, IB9387, IB9389, IB939firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek IP-series models: IP9165, IP9171, IP9172, IP9181, IP9191firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek IT-series model: IT9389firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek MA-series models: MA9321, MA9322firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek MS-series models: MS9321, MS9390firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Vivotek TB-series model: TB9330firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1,
Estimated exposure
largeestimated tens of thousands of internet-exposed camera systems (order of 10,000-100,000), with a larger installed base on private networks — Internet-wide scans have long shown Vivotek cameras in the tens of thousands reachable online, and the 36 affected 9-series model lines across many firmware releases cover a broad share of that exposed professional-lineup fleet, so this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c.

Weakness
CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber

In the news

No ingested article mentions this CVE yet.