Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

The researcher who discovered the vulnerability saw more than 2,500 internet-exposed devices.

TP-Link vulnerabilities

TP-Link has patched a serious vulnerability that can be exploited to take control of more than 32 of its VIGI C and VIGI InSight series professional surveillance camera models.

The security hole, tracked as CVE-2026-0629 and classified as high severity, is described in a TP-Link advisory published last week as an authentication bypass flaw affecting the password recovery feature in the cameras’ local web interface.

The flaw, according to TP-Link, “allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state”, enabling them to gain full admin access to the device.

The vulnerability was discovered by Arko Dhar, co-founder and CTO of IoT cybersecurity company Redinent Innovations.  

Dhar told SecurityWeek that an attacker could exploit the vulnerability to gain complete access to the targeted camera, including its video feed and other functionality. 

The researcher warned that the flaw can be exploited remotely and noted that at the time of discovery in October 2025 he had identified more than 2,500 internet-exposed cameras worldwide that may have been vulnerable to attacks. 

Advertisement. Scroll to continue reading.

However, he only looked for instances of a single affected camera model. The actual number of exposed devices across all impacted models may be much higher. 

TP-Link’s VIGI cameras are used by organizations in over 36 countries and regions, primarily in Europe, Southeast Asia, and the Americas.

It’s not uncommon for threat actors to target TP-Link products in their attacks. CISA’s Known Exploited Vulnerabilities (KEV) catalog currently lists five TP-Link flaws exploited in attacks in recent years, but they all impact wireless routers and range extenders.

Nevertheless, hackers often exploit vulnerabilities in other camera brands in the wild, making it important for organizations not to ignore the recently disclosed flaw. 

Related: No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking

Related: Critical Vulnerabilities Patched in TP-Link’s Omada Gateways

Related: CISA Warns of Avtech Camera Vulnerability Exploited in Wild

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Cyera has appointed Naveen Palavalli as Chief Marketing Officer.

Connie Devine has been promoted to Chief Information Security Officer at Phillips 66.

Jeff Lunglhofer becomes Chief Security Officer at Coinbase, replacing Philip Martin.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.