A critical security flaw in TP-Link’s VIGI surveillance cameras allows attackers on local networks to change admin passwords without permission. CVE-2026-0629 identifies a critical flaw in the camera’s web interface password recovery, rated 8.7 on the CVSS v4.0 scale.
The authentication bypass issue arises from incorrect client-side state handling in the password recovery function. Attackers on the LAN can exploit this weakness to reset the admin password without verification, gaining full access to the device.
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
The vulnerability can be easily exploited by anyone with LAN access, as it doesn’t need elevated privileges, user interaction, or network attacks. Attackers can easily compromise confidentiality, integrity, and availability through nearby network access.
Attackers can exploit vulnerabilities in VIGI cameras to gain full control, allowing them to change settings and disable security features.
Affected Products and Mitigations:
| Product Series |
Models |
Fixed Version |
| VIGI Cx45 |
C345, C445 |
≥ 3.1.0 Build 250820 Rel.57668n |
| VIGI Cx55 |
C355, C455 |
≥ 3.1.0 Build 250820 Rel.58873n |
| VIGI Cx85 |
C385, C485 |
≥ 3.0.2 Build 250630 Rel.71279n |
| VIGI C340S |
C340S |
≥ 3.1.0 Build 250625 Rel.65381n |
| VIGI C540S |
C540S, EasyCam C540S |
≥ 3.1.0 Build 250625 Rel.66601n |
| VIGI InSight Sx45 |
S245, S345, S445 |
≥ 3.1.0 Build 250820 Rel.57668n |
| VIGI InSight Sx55 |
S355, S455 |
≥ 3.1.0 Build 250820 Rel.58873n |
Complete patch details for all affected products can be found on TP-Link’s official support channels. TP-Link has
released firmware updates for all affected devices to fix vulnerabilities. Organizations should download and install the latest versions right away from the Download Center.