Cyberpress
Critical Vivotek Vulnerability Enables Remote Code Execution
First seen 22 Jan 2026, 21:42 UTC
•

•48.3
Export
Article Content
Browse articles
A critical vulnerability in Vivotek legacy firmware allows unauthenticated attackers to execute arbitrary commands with root privileges. Tracked as CVE-2026-22755, it affects numerous camera models and is particularly concerning for organizations using outdated surveillance systems. The flaw is found in the upload_map.cgi script, which improperly processes user-supplied filenames.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
Date unknown
Vulnerability discovered
Recent
Exploit released
Date unknown
Patch released
More articles in this cluster
Continue Reading
Google Addresses Unreported Chrome Zero-Day Vulnerability
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Apple Fixes Zero-Day Vulnerability in Software Update
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
Cisco Addresses AsyncOS Zero-Day Exploited by Threat Actors