Vivotek Camera Flaw CVE-2026-22755: NC Plant Network Risk

CISA flagged a Vivotek IP camera command-injection flaw on Sept 29, 2026, 259 days after public disclosure. The NC plant checklist. Call (336) 886-3282.

Cover Image for Vivotek Camera Flaw CVE-2026-22755: NC Plant Network Risk

Does this apply to you? If your building has IP cameras, probably. The specific product is Vivotek, and the models are listed below, but the useful part of this story is not the brand. It is that the flaw was public in January and the advisory that would actually reach a plant owner arrived on September 29.

On that date CISA published an advisory about a flaw that lets someone run commands, potentially as root, on 37 models of Vivotek IP camera with no password. The flaw was not new: it went into the public vulnerability record on January 13, 2026, and the technical write-up followed seven days later. By September a public proof of concept existed, which is what prompted the advisory.

259 days. That is the number worth your attention, and the question it asks is not about cameras: who in your company would have seen either announcement?

What did CISA actually publish?

CISA's advisory ICSA-26-272-03 covers CVE-2026-22755, a command injection flaw in Vivotek camera firmware. CISA scores it 10.0, the maximum, under both CVSS v3.1 and v4.0, and says successful exploitation may allow "remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system." No credentials, no user interaction, low attack complexity.

Two things in it matter more than the score. CISA found the exploit rather than the flaw: the advisory states that "CISA discovered a public proof of concept as authored by indoushka and reported it to VIVOTEK," so the advisory is downstream of a public exploit. And nobody has reported an attack: the advisory says plainly that "no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time." That is a real limit on the urgency, and anyone telling you your cameras are under attack this week is going past the evidence.

On the score, an apparent disagreement turns out not to be one. CISA says 10.0; the National Vulnerability Database record, scored by the Akamai researcher who published the analysis, says 9.3. The two vectors are identical on severity. The 9.3 is that same score adjusted down because the researcher recorded a proof-of-concept exploit rather than a confirmed attack.

Want a straight answer on what your cameras can reach? Preferred Data Corporation has been designing networks for North Carolina manufacturers out of High Point since 1987, 39 years. Call (336) 886-3282 or ask for a camera network review.

Why did it take eight and a half months to reach you?

DateWhat happenedWho would plausibly have seen it
January 13, 2026CVE-2026-22755 published to the NVDVulnerability feeds. Not scanners, for the reason below
January 20, 2026Akamai's security research team published the mechanism: /cgi-bin/admin/upload_map.cgi, shell characters smuggled in a filename, commands running as root, per AkamaiResearchers, red teams
Sometime before SeptemberA public proof of concept appearedWhoever reads exploit repositories
September 29, 2026CISA published ICSA-26-272-03Plant managers, finally

The right-hand column holds the explanation. The NVD record carries no structured product data and is marked "Deferred," so a scanner has nothing to match your cameras against even if somebody runs one. The information existed; the machinery that would have surfaced it to you did not.

Thirty-seven model numbers appear in the record, and they appear only as free text in a description field rather than as structured data. Here they are, so you can check yours here:

FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391, FE9180, FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371, IB9381, IB9387, IB9389, IB939, IP9165, IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330

Most are ordinary domes, fisheyes and bullets, the kind that sit over a dock door or a parts cage in a Davidson County moulding shop, with some multi-sensor and thermal units.

Note what the record does not say. It enumerates 20 specific firmware builds rather than a range, from 0100a up to 0125c, including strings like 0121d_48573_1 and 012502. Match your build against that list exactly: do not assume everything between the endpoints is covered, and do not clear a camera because its build looks newer than one listed.

Key takeaway: Eight and a half months is just how the plumbing works. Disclosure runs through channels built for security teams, and a 60-person shop in Thomasville does not have one. The ICS advisory is the first notice that ever reaches an owner, and it arrives whenever CISA happens to look.

Can you actually do what the advisory tells you to do?

Here the advisory and a real building part company, and this is where most coverage of CVE-2026-22755 is going wrong.

CISA's remediation line is that "VIVOTEK has addressed this issue and encourages users to download and install the latest firmware available." That reads as actionable. Try executing it.

Checked on October 1, 2026, Vivotek's security advisory page shows a latest-update date of September 2, 2026, just under four weeks before the CISA advisory, and no entry for CVE-2026-22755 or upload_map.cgi. The fix may be documented in firmware release notes in the download center, where CISA's remediation link points. What is missing is a published advisory you could search for that maps this CVE to a specific build on a specific model.

So "install the latest firmware" is the entire instruction. On a camera estate, that assumes a lot:

What the advisory assumesWhat is usually true in a 20-250 person NC plant
You know which models you haveThe models are on an invoice from a low-voltage contractor, filed by job number, not by asset
You know the running firmwareNobody has logged into a camera since commissioning
Someone owns firmware updatesThe system was sold, installed and warrantied by the alarm or cabling company, whose contract usually does not include firmware maintenance
Updating is routineCamera firmware updates occasionally brick the unit, and a bricked dome at 30 feet is a lift rental
A fixed build exists for your modelSome units in service predate the branch that got fixed
Somebody can log into the switch the cameras hang offOften nobody can. The credentials left with a person, years ago

That last row is not an edge case. In 70-person plants it is close to the normal condition, and it is why most segmentation advice goes unexecuted. An article that tells you to build a camera VLAN without asking whether anyone can reach the switch has skipped the step that decides everything.

What actually closes this, firmware or no firmware?

Network position. CISA's mitigation list for this advisory leads with it: minimize network exposure, keep the devices off the internet, isolate them behind a firewall from the business network, use a VPN for remote access that is genuinely needed.

Here is that translated into things a plant manager can start, in the order they should happen.

Find the paperwork. Pull the folder for whichever project installed the cameras, and get the installer's name and the model numbers. An hour in a filing cabinet, and it unblocks everything else.

Ask one question of whoever manages your network, in writing: are any cameras or recorders reachable from the internet, and can the camera network reach the file server, the ERP or accounting? Do not run this test yourself. It needs access to your firewall and your public addresses, and an article that tells a plant manager to go port-scan their own building is pretending. A vague answer is itself your finding. Nobody to ask is a larger one, and the first to act on.

Establish who can log into the network gear. Before anyone can segment anything, somebody has to hold credentials for the switch and the firewall. If nobody does, that is a scheduled job with a console cable, and it comes first.

Name an owner for camera firmware, in writing, this week. If that is the alarm company, put it in the service agreement with a response expectation. If the answer is nobody, you have found something more consequential than this CVE.

The step that gets skipped is the recorder's cloud account, still running the password the integrator set in 2019. That is what gets used.

When we audit a manufacturing network in the Piedmont Triad, the camera segment is reliably among the weakest in the building, usually alongside the building-automation controllers. The reason is not negligence. Cameras go in during construction, installed by a trade contractor, on whatever port the electrician had live that day, and the IT provider arrives afterwards and is never told. That handoff is where the exposure gets manufactured, and it is a contract problem before it is a firewall problem.

Key takeaway: Segmentation does not make a compromised camera harmless. The attacker still owns that device, can reach every other device on the same segment to attack in turn, and can use your outbound bandwidth. What it removes is the route from the camera to your file server and your ERP. That is the difference between a camera replacement and an incident with lawyers in it.

Not sure what is on your plant network? A one-time segmentation review survives the next advisory as well as this one. Preferred Data Corporation covers manufacturers and furniture plants on-site within 200 miles of High Point. Call (336) 886-3282.

Does this change how you buy cameras?

Yes, and this is the part that outlasts the CVE. Put these in the next camera or access-control quote you sign. None of them need an engineer in the room.

  • Where does this vendor publish security advisories? A vendor with a findable, current advisory page is telling you something a spec sheet cannot.
  • How long will firmware be supported on these exact models, in writing? "Latest firmware" means nothing on a model that stopped receiving any.
  • Who applies that firmware, within what window of a critical advisory? Name a party. If the installer will not take it, your IT provider has just inherited it and should be told.

Our view, and it is not popular with integrators who sell on image quality: answer the firmware question before the lens question. A camera that resolves beautifully and stops getting updates in three years is a worse buy than an adequate one still patched in year seven.

Frequently Asked Questions

How do I tell whether my cameras are on the list?

Vivotek models start with a two-letter series code, FD, FE, IB, IP, IT, MA, MS or TB, followed by digits, but the digit count in the published list is not consistent: it includes IB939, FD8365v2 and IB93587LPR alongside more typical entries like FD9389. Compare against the list above rather than against a pattern.

And treat a near-match as a match until somebody tells you otherwise. Both CISA and the NVD record carry those same odd strings, so at least one is likely a slip somewhere upstream: a camera labelled IB9391 or IB9387LPR is close enough to a listed entry that you should not rule it out on a character difference. Ask Vivotek or your integrator in writing and treat it as in scope while you wait. Same if the system was sold under an integrator's own brand: ask what hardware is underneath.

Is anyone attacking this right now?

Not that CISA has been told, as of its September 29 advisory. A public proof of concept exists, which is why the advisory was written. That makes it a flaw with a published recipe and no confirmed campaign: act deliberately this month, do not panic this afternoon.

The installer put the cameras on their own recorder. Is that segmentation?

Usually not. A recorder collecting the camera feeds says nothing about what the cameras and the recorder can reach on your network, and the recorder itself is often the one device deliberately given a path out to the internet so a phone app works. Segmentation is a property of the switch and firewall configuration, not of the camera system's own wiring.

Our cameras cannot be updated. Now what?

Then network position is your whole control, and you can have it this quarter rather than next budget year: no route to business systems, no inbound path from the internet. Put the replacement in the capital plan with the firmware-support question settled first. A camera you cannot patch is a risk you have decided to accept, which is defensible as long as somebody decided it rather than inherited it.

What would an attacker do with a camera?

Use it as a foothold to reach better targets on the same network, rent it out as part of a botnet, or watch. The first is what costs an NC manufacturer money: it turns a device cheaper than a laptop into the way into your production and financial systems. Watching a shop floor is rarely the motive.

Does our cyber insurance care?

In our experience helping clients fill these in, yes: applications increasingly ask whether operational and IoT devices are segmented from business systems. If you are not certain of your answer, find out before the renewal rather than after a claim, and ask your broker how your carrier treats an application answer that later proves wrong.

How fast should a private company move on an ICS advisory?

Federal civilian agencies work to risk-based timelines under CISA's Binding Operational Directive 26-04, issued June 10, 2026, which sorts a flaw on four factors: internet exposure, whether it is in CISA's exploited-vulnerability catalog, whether exploitation is automatable, and whether it yields total or partial control. That binds agencies rather than companies, and this CVE is not in the catalog, so nothing here puts you on a federal clock. The sorting logic is still the best free model available, and it points where we do: internet exposure is the factor that moves a deadline by an order of magnitude, so settle that question first.

Where do I start, and how long does it take?

Pull the install paperwork and find the models and the installer. Then send the one-sentence question above to whoever manages your network and put a date on the email. Those two answers decide everything else, and one of them is somebody else's job, which is the point. If the paperwork is missing or nobody answers, call (336) 886-3282 or start here.