Critical Flaw in Widely Used VIVOTEK Security Cameras Could Allow Full Takeover
CISA has issued an advisory covering a wide range of VIVOTEK camera models, including popular V, C, S and Dome series units commonly used for business and property surveillance. The flaw, tracked as CVE-2026-22755, could allow an attacker to remotely execute commands on the device, potentially gaining root level access and full control of the camera.
Because these cameras are often connected directly to business networks and the internet for remote monitoring, a successful attack could expose live video feeds, allow the device to be used as a foothold into the wider network, or turn it into part of a botnet. Given the large number of affected models, businesses using VIVOTEK cameras for security or CCTV purposes should check whether their devices are on the affected list and apply any vendor firmware updates as soon as they are released.
Until patches are available, businesses should ensure cameras are not directly exposed to the internet and are segmented from critical business systems.