TP-Link patched a high-severity authentication bypass vulnerability in its VIGI surveillance camera product line that allows an attacker with local network (LAN) access to reset the administrator password and take full control of affected devices. Tracked as CVE-2026-0629 (CVSS v4.0 8.7), the issue is in the cameras’ local web interface password recovery workflow, where improper reliance on client-side state enables password reset without verification, requiring no privileges or user interaction.
Successful exploitation can enable attackers to access or manipulate live/recorded video, change configurations, disable security features, and potentially use compromised cameras as a pivot for lateral movement or botnet/DDoS activity. Reporting attributes the discovery to Arko Dhar (Redinent Innovations) and notes broad model impact across VIGI C and VIGI InSight lines (reported as 28 series in one account and 32+ models in another); one researcher assessment identified 2,500+ internet-exposed potentially vulnerable devices from checks of a single model, suggesting wider exposure where cameras are reachable from the internet despite the LAN-oriented attack vector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On January 20, 2026, reports publicly described CVE-2026-0629 as a high-severity authentication bypass caused by client-side state manipulation that lets an attacker on the local network reset the admin password and gain full administrative control.
By January 2026, TP-Link had released firmware updates for more than 32 affected VIGI C and VIGI InSight camera models to fix CVE-2026-0629, an authentication bypass in the password recovery feature.
In October 2025, researcher Arko Dhar identified more than 2,500 internet-exposed TP-Link VIGI cameras vulnerable to CVE-2026-0629 by checking a single model, indicating broader exposure was likely.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.