CVE-2026-22755: Legacy Vivotek Camera Firmware Command Injection in upload_map.cgi

Published Jan 13, 2026
·
Updated

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d485731, 0122e, 0124d485731, 012501, 012502, 0125c.

Affected Software

1 affected component
Vivotek Firmware>=0100a<=0125c

Event History

Jan 13, 2026
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Feb 19, 58052
Event
via FIRST·01:34 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-22755?

CVE-2026-22755 is considered a high-severity vulnerability due to its exploitation potential through default login credentials.

2

How do I fix CVE-2026-22755?

To fix CVE-2026-22755, change the default login credentials to strong, unique passwords and ensure device firmware is updated.

3

What devices are affected by CVE-2026-22755?

CVE-2026-22755 affects several Vivotek camera models including FD8365, FD9165, and FD9391 among others.

4

What is command injection in CVE-2026-22755?

Command injection in CVE-2026-22755 refers to the improper handling of special characters that can be exploited to execute arbitrary commands on the device.

5

Is CVE-2026-22755 an unpatched vulnerability?

Yes, CVE-2026-22755 remains unpatched for many legacy Vivotek devices, making users particularly vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203