Akamai’s Security Intelligence and Response Team (SIRT) disclosed a critical remote command injection vulnerability in Vivotek legacy IP camera firmware tracked as CVE-2026-22755 (reported CVSS 9.3). The flaw enables unauthenticated attackers to execute arbitrary commands as root by abusing the camera’s file upload handling in the upload_map.cgi CGI endpoint, where a user-controlled filename is incorporated into a formatted string and then passed to a shell via system() without proper sanitization, allowing shell metacharacter injection (e.g., ;).
Technical reporting indicates exploitation hinges on crafting an upload that satisfies several implementation constraints (e.g., upload size limits and firmware validation behaviors) and invoking the upload path in a way that preserves required environment variables; researchers demonstrated command execution by embedding commands in the filename and observing uid=0 output. The issue reportedly impacts dozens of models (36 cited) across multiple Vivotek product lines and is amplified by findings that some affected legacy devices may ship or operate without passwords set by default, increasing the likelihood of opportunistic compromise and downstream abuse (e.g., botnet recruitment and DDoS activity) in environments still running legacy surveillance infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting revealed that many affected legacy Vivotek cameras may ship without passwords, making exploitation likely unauthenticated in many cases. Additional technical analysis and a proof of concept showed attackers could inject commands through POST_FILE_NAME during firmware upload, affecting 36 legacy camera models and enabling full device compromise and botnet abuse.
Akamai SIRT disclosed CVE-2026-22755, a critical remote command injection vulnerability in legacy Vivotek surveillance camera firmware. The flaw in upload_map.cgi allows arbitrary command execution via unsanitized filenames passed to a system shell, potentially yielding root access on affected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.