CISA has published ICSA-26-272-03 for VIVOTEK camera firmware after a CSAF advisory described a vulnerability that may allow remote command execution on affected devices, potentially with root privileges and full compromise of the camera system. The impacted families called out in the advisory summary include V Series models FD9187, FD9189, FD9365, FD9387, FD9389, FD9391, FE9191, FE9382, FE9391, IB9365, IB9387, and IB9389, plus C Series model FE9180, all mapped to CVE-2026-22755. The summary was truncated, so defenders should pull the full CISA advisory and VIVOTEK CSAF document before final scoping: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03.
The urgency is not abstract. IP cameras are usually treated as facilities equipment, but operationally they are Linux-based network computers with web services, RTSP, ONVIF/UPnP-style discovery, storage, NTP/DNS, and sometimes outbound cloud connectivity. A root-level RCE on a camera is a foothold inside trusted physical-security networks, a surveillance-integrity risk, and a launch point for lateral movement if the camera VLAN can reach user, server, badge, NVR, or management segments. Treat internet-exposed VIVOTEK devices and flat camera networks as incident candidates until proven otherwise.
Technical Analysis
Affected products and versions: the advisory summary explicitly names the models above and maps them to CVE-2026-22755. It does not provide a complete fixed-version matrix or CVSS vector in the supplied text. Do not guess either. Use the CSAF product-status sections to enumerate exact firmware branches, affected version ranges, first fixed releases, and mitigations. Where your VMS or asset inventory stores only model names, normalize aliases now: FD/FE/IB prefixes map to dome/fisheye/bullet-style cameras, but model and firmware build are what matter.
Likely defensive attack chain: exploitation of embedded camera services commonly reaches command execution through the management web application, CGI handlers, API endpoints, firmware update logic, or network service parameters that are passed to a shell. On VIVOTEK-class devices, defenders should assume the exposed surface includes HTTP/HTTPS management, RTSP on TCP/554, discovery services, and vendor cloud/update agents. Successful exploitation would typically present as an unusual HTTP request to the camera followed by process execution as root, configuration change, credential access, a new listener, or an outbound connection from the camera to an external host.
Exploitation requirements: for many camera RCEs, the key variables are whether authentication is required, whether the endpoint is reachable from user networks, and whether the device is internet-facing. The provided summary does not state pre- versus post-auth exploitation. Until the CSAF is reviewed, triage as if unauthenticated remote exploitation is possible for exposed management interfaces.
Exploitation status: the supplied item does not confirm a public PoC, active exploitation, ransomware use, or CISA KEV inclusion. Absence of evidence is not safety. Camera vulnerabilities are routinely scanned for because default credentials, forgotten firmware, and exposed UIs are common. Prioritize internet-facing devices, camera VLANs with broad east-west access, and sites where cameras share segments with NVRs, access-control panels, or building-automation systems.
Immediate scoping questions for your IR and VM teams:
- Do we have VIVOTEK FD9187/FD9189/FD9365/FD9387/FD9389/FD9391/FE9180/FE9191/FE9382/FE9391/IB9365/IB9387/IB9389 or related V/C series inventory?
- Are management interfaces reachable from user networks, VPN, vendor remote support, or the internet?
- Can cameras initiate outbound connections beyond NTP/DNS/update allowlists?
- Are camera syslog, firewall, proxy, and NVR authentication logs retained centrally?
- Is there any evidence of new admin accounts, changed DNS/NTP, disabled logging, unexpected firmware, or reboots?
Detection & Response
Run these hunts against camera subnets and any jump hosts used to administer them. Replace the example subnets with your CCTV/physical-security ranges. The highest-fidelity early signal is a camera making outbound connections that are not to approved NVR, VMS, DNS, NTP, or vendor update destinations.
---
title: VIVOTEK Camera Web Service Spawning Shell or Downloader
id: 8d5f4f2a-7a7b-4d62-9c65-202602275501
status: experimental
description: Detects embedded Linux process execution consistent with exploitation of a camera web/CGI service leading to shell, downloader, or post-exploitation tooling. Forward camera syslog or sensor Linux audit data where available.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03
- https://attack.mitre.org/techniques/T1059/004/
- https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/02/13
tags:
- attack.execution
- attack.t1059.004
- attack.command_and_control
- attack.t1105
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/httpd'
- '/lighttpd'
- '/nginx'
- '/boa'
- '/goahead'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/busybox'
- '/wget'
- '/curl'
- '/nc'
- '/netcat'
- '/chmod'
- '/killall'
condition: selection_parent and selection_child
falsepositives:
- Vendor firmware scripts during legitimate updates
- Camera health checks; baseline parent/child pairs before broad deployment
level: high
---
title: Suspicious Command Line in Embedded Camera Syslog
id: 41a6d5fb-3a4e-4e50-9e62-202602275502
status: experimental
description: Flags shell metacharacters or download-and-execute patterns appearing in camera process or web logs forwarded via syslog. Intended for high-value network zones rather than broad enterprise Linux fleets.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/02/13
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection_img:
CommandLine|contains:
- 'wget http'
- 'curl http'
- '| sh'
- '|sh'
- ';id'
- '; id'
- 'chmod +x'
- '/tmp/'
- '/var/tmp/'
filter_legit_update:
CommandLine|contains:
- 'ntpdate'
- 'udhcpc'
- 'crond'
condition: selection_img and not filter_legit_update
falsepositives:
- Firmware upgrade jobs if update paths use /tmp
- Managed service scripts; scope to camera subnets in the SIEM
level: high
let CameraSubnets = dynamic(["10.40.0.0/16", "192.168.50.0/24"]);
let ApprovedDest = dynamic(["10.0.0.5", "10.0.0.6", "10.20.10.15"]);
let CameraIPs = toscalar(print iprange=CameraSubnets | mv-expand iprange to typeof(string));
union isfuzzy=true
(DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where ipv4_is_in_range(LocalIP, "10.40.0.0/16") or ipv4_is_in_range(LocalIP, "192.168.50.0/24")
| where ActionType == "ConnectionSuccess"
| where RemoteIP !in (ApprovedDest) and not(ipv4_is_private(RemoteIP))
| project TimeGenerated, DeviceName, LocalIP, LocalPort, RemoteIP, RemotePort, InitiatingProcessFileName, InitiatingProcessCommandLine),
(CommonSecurityLog
| where TimeGenerated > ago(7d)
| where ipv4_is_in_range(SourceIP, "10.40.0.0/16") or ipv4_is_in_range(SourceIP, "192.168.50.0/24")
| where DestinationIP !in (ApprovedDest) and not(ipv4_is_private(DestinationIP))
| project TimeGenerated, DeviceVendor, DeviceProduct, SourceIP, SourcePort, DestinationIP, DestinationPort, Protocol, Message)
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Samples=make_set(Message, 5) by SourceIP=column_ifexists("SourceIP", LocalIP), DestinationIP, DestinationPort
| order by Connections desc;
// Hunt inbound HTTP attempts to camera management interfaces with shell metacharacters in URI or payload. Requires firewall/proxy/Zeek/web logs in Sentinel.
let BadTokens = dynamic([";", "`", "$(", "| sh", "wget", "curl", "chmod", "/tmp/", "busybox"]);
union isfuzzy=true
(CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationPort in (80, 443, 554, 8000, 8080)
| where Message has_any (BadTokens)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, RequestURL=extract(@"(?i)(GET|POST) ([^ ]+)", 2, Message), Message),
(Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any (BadTokens)
| where SyslogMessage has_any ("httpd", "cgi", "boa", "goahead", "lighttpd", "rtsp", "vivotek")
| project TimeGenerated, HostIP, Computer, Facility, SeverityLevel, SyslogMessage)
| order by TimeGenerated desc;
-- Hunt management hosts for tools/sessions touching VIVOTEK camera services after the advisory window.
-- Scope CameraSubnet to your physical security range before scheduling.
LET CameraSubnet = "10.40.0.0/16"
SELECT Pid, Ppid, Name, CommandLine, Username, CreateTime, Exe
FROM pslist()
WHERE CommandLine =~ "(nmap|masscan|curl|wget|nc|netcat|telnet|ssh|rtsp|onvif)"
AND CommandLine =~ "(10\\.40\\.|192\\.168\\.50\\.|FD9187|FD9387|FE9191|IB9387|vivotek)"
-- Check servers and jump hosts for established connections to camera web/RTSP services.
SELECT Pid, Name, LocalAddr, LocalPort, RemoteAddr, RemotePort, Status
FROM netstat()
WHERE Status =~ "ESTABLISHED"
AND RemotePort in (80, 443, 554, 8000, 8080)
AND RemoteAddr =~ "^(10\\.40\\.|192\\.168\\.50\\.)"
#!/usr/bin/env bash
# VIVOTEK CVE-2026-22755 exposure triage for Linux utility hosts / NVR jump boxes.
set -euo pipefail
CAM_NETS="10.40.0.0/16 192.168.50.0/24"
OUT="vivotek_triage_$(date +%Y%m%d_%H%M%S)"
mkdir -p "$OUT"
# 1) Discover live camera services without aggressive service probes.
for net in $CAM_NETS; do
nmap -Pn -p80,443,554,8000,8080 --open -oG "$OUT/nmap_$(echo "$net" | tr '/.' '__').gnmap" "$net" >/dev/null 2>&1 || true
done
# 2) Pull headers/banners only. Do not attempt exploitation.
awk '/Ports:/{print $2}' "$OUT"/*.gnmap | sort -u > "$OUT/live_hosts.txt"
while read -r ip; do
[ -z "$ip" ] && continue
curl -k -sS --max-time 4 -I "http://$ip/" | sed -n '1,12p' > "$OUT/http_$ip.txt" 2>&1 || true
curl -k -sS --max-time 4 -I "https://$ip/" | sed -n '1,12p' > "$OUT/https_$ip.txt" 2>&1 || true
done < "$OUT/live_hosts.txt"
# 3) Flag outbound camera connections on the local firewall/NAT logs if present.
for net in $CAM_NETS; do
base="$(echo "$net" | cut -d/ -f1 | cut -d. -f1-3)"
grep -E "$base" /var/log/syslog /var/log/messages 2>/dev/null | grep -Ei 'DST=|dpt=(80|443|554|8000|8080)|NEW|ESTABLISHED' | tail -n 200 > "$OUT/fw_${base}.log" || true
done
# 4) Produce review list.
{
echo "Live hosts:"; cat "$OUT/live_hosts.txt"
echo; echo "Potential VIVOTEK banners:"; grep -Eil 'vivotek|network camera|fd918|fe918|fe919|ib936|ib938' "$OUT"/http_*.txt "$OUT"/https_*.txt 2>/dev/null || true
} > "$OUT/review.txt"
echo "Wrote $OUT/review.txt. Patch only via VIVOTEK CSAF fixed firmware; do not run exploit checks against production cameras."
Remediation
- Confirm exact exposure from the authoritative source. Open CISA ICSA-26-272-03 and the linked VIVOTEK CSAF. Build a table with model, current firmware, affected/fixed status, first fixed version, management exposure, internet reachability, VLAN, NVR owner, and business criticality. Do not rely on the truncated summary list as complete.
- Remove direct internet reachability immediately. Block inbound DNAT/port-forward to camera UI/RTSP, disable UPnP on edge gear, and search Shodan-like exposure internally by validating public firewall rules. If remote viewing is required, place it behind a hardened VMS/proxy with MFA and no direct camera administration.
- Segment aggressively. Cameras should initiate only to approved NVR/VMS, DNS, NTP, and vendor update FQDNs/IPs. Deny camera-to-user, camera-to-server, camera-to-domain-controller, and camera-to-internet by default. Log all denies and alert on approved-list violations.
- Patch using vendor-signed firmware only after validating model and branch. Stage one camera per model, verify stream integrity, analytics, recording, ONVIF/VMS reconnect, time sync, certificates, and rollback procedure. Reboot windows are security controls too; do not leave half-upgraded fleets.
- Rotate credentials after patching where compromise cannot be excluded: local admin, VMS service accounts, ONVIF users, SNMP communities, Wi-Fi PSKs on connected bridges, and any reused NVR credentials. Disable unused accounts and services.
- Preserve evidence before wiping suspect devices: export logs/config if supported, capture firewall flows, record firmware hash/version, note uptime/reboots, and image or replace the unit if root compromise is plausible. A factory reset without forensic capture may destroy attribution and persistence artifacts.
- Hunt for persistence after remediation: unexpected users, changed DNS/NTP, disabled syslog, modified startup scripts, unknown certificates, new outbound peers, and firmware versions that do not match your deployment record.
- Add compensating detections to the SOC runbook: weekly camera egress baseline diff, alerting on camera VLAN connections to non-approved destinations, and a vulnerability-management SLA exception process for devices that cannot be patched due to operations. If a device cannot be patched, isolate it, restrict UI access to a dedicated admin jump host, and document risk acceptance with an expiration date.
Related Resources
Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.