Back

HIGH

Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras

Published Jan 16, 2026

Description

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TPLink
Published Jan 16, 2026
Updated Feb 26, 2026
Reserved Jan 6, 2026
CISA Vulnrichment
Updated Jan 17, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner TPLink
Published Jan 16, 2026
Updated Feb 26, 2026
Exploited since n/a
EUVD-2026-2932