Vulnerabilities

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

The researcher who discovered the vulnerability saw more than 2,500 internet-exposed devices.

TP-Link vulnerabilities

TP-Link has patched a serious vulnerability that can be exploited to take control of more than 32 of its VIGI C and VIGI InSight series professional surveillance camera models.

The security hole, tracked as CVE-2026-0629 and classified as high severity, is described in a TP-Link advisory published last week as an authentication bypass flaw affecting the password recovery feature in the cameras’ local web interface.

The flaw, according to TP-Link, “allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state”, enabling them to gain full admin access to the device.

The vulnerability was discovered by Arko Dhar, co-founder and CTO of IoT cybersecurity company Redinent Innovations.  

Dhar told SecurityWeek that an attacker could exploit the vulnerability to gain complete access to the targeted camera, including its video feed and other functionality. 

The researcher warned that the flaw can be exploited remotely and noted that at the time of discovery in October 2025 he had identified more than 2,500 internet-exposed cameras worldwide that may have been vulnerable to attacks. 

Advertisement. Scroll to continue reading.

However, he only looked for instances of a single affected camera model. The actual number of exposed devices across all impacted models may be much higher. 

TP-Link’s VIGI cameras are used by organizations in over 36 countries and regions, primarily in Europe, Southeast Asia, and the Americas.

It’s not uncommon for threat actors to target TP-Link products in their attacks. CISA’s Known Exploited Vulnerabilities (KEV) catalog currently lists five TP-Link flaws exploited in attacks in recent years, but they all impact wireless routers and range extenders.

Nevertheless, hackers often exploit vulnerabilities in other camera brands in the wild, making it important for organizations not to ignore the recently disclosed flaw. 

Related: No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking

Related: Critical Vulnerabilities Patched in TP-Link’s Omada Gateways

Related: CISA Warns of Avtech Camera Vulnerability Exploited in Wild

Related Content

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Vulnerabilities

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version