การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Application Security

Severe Command Execution Flaw Affects VIVOTEK Camera Firmware

FORTSECURE GLOBAL· 2026-09-29🛰 CISA Cybersecurity Advisories
#Application Security#Vulnerability#IoT Security#Command Injection

VIVOTEK camera firmware contains a critical vulnerability that allows attackers to gain root-level command execution access.

Security Implications for Surveillance Systems

A critical security vulnerability (CVE-2026-22755) has been identified in several VIVOTEK camera models, including the FD9187, FD9189, FD9365, FD9387, and FD9389 series. This flaw permits attackers to achieve remote command execution, potentially with root privileges. Such unauthorized access grants an attacker complete control over the device, which could lead to surveillance footage theft, manipulation, or the integration of the camera into a botnet.

Protective Measures

  • Firmware Updates: It is imperative to identify your specific device model and apply the latest firmware updates from the official VIVOTEK support portal.
  • Isolate IoT Devices: Avoid exposing surveillance cameras directly to the internet. Deploy them on an isolated network segment (VLAN) without outbound access to sensitive internal business systems.
  • Credential Management: Change default login credentials immediately. Use strong, unique passwords for every device to prevent brute-force attacks from escalating the impact of this vulnerability.
  • Access Control: Implement firewall rules to permit traffic only from authorized security monitoring stations, blocking all other attempts to interface with the camera’s management console.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Tue, 29 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Tue, 29 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog