CVE-2026-22755
largeOS Command Injection in Vivotek 9-Series IP Camera Firmware
CVE-2026-22755 is an OS command injection flaw (CWE-77, improper neutralization of special elements used in a command) in the firmware of 36 Vivotek network camera models spanning the FD, FE, IB, IP, IT, MA, MS and TB 9-series lines. Per the CVSS 4.0 vector, it is exploitable over the network with no privileges required and no user interaction, meaning an attacker can send crafted input to a network-facing service in the camera firmware and have arbitrary operating-system commands executed on the device. Successful exploitation carries high impact to the camera's confidentiality, integrity and availability - and to subsequent systems - consistent with full device compromise and potential lateral movement into the surrounding surveillance network. Any deployment running one of the listed models on one of the 20 listed firmware module versions (0100a through 0125c) is affected, with directly internet-exposed cameras at greatest risk. No public proof of concept or confirmed in-the-wild exploitation is known (not yet in CISA KEV), but EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile), making this a high-priority patching target.
What to do: Inventory all Vivotek cameras and compare installed firmware module versions against the affected list (0100a through 0125c on the listed models); upgrade to Vivotek's patched firmware as soon as a fixed release is identified, since the advisory data specifies no fixed version. Until patched, avoid exposing affected cameras' web interfaces directly to the internet - restrict management access to isolated VLANs or VPN - and monitor devices for exploitation attempts, prioritizing internet-facing units given the 20.7% EPSS (97th percentile).
| Vivotek FD-series models: FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek FE-series models: FE9180, FE9181, FE9191, FE9381, FE9382, FE9391, FE9582 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek IB-series models: IB9365, IB93587LPR, IB9371, IB9381, IB9387, IB9389, IB939 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek IP-series models: IP9165, IP9171, IP9172, IP9181, IP9191 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek IT-series model: IT9389 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek MA-series models: MA9321, MA9322 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek MS-series models: MS9321, MS9390 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
| Vivotek TB-series model: TB9330 | firmware module versions 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c.
- Weakness
- CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber
In the news0 stories
No ingested article mentions this CVE yet.