CVE-2026-22755

Jan. 14, 2026, 4:26 p.m.

9.3
Critical

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c.

Product(s) Impacted

Vendor Product Versions
Vivotek
  • Fd8365
  • Fd8365v2
  • Fd9165
  • Fd9171
  • Fd9187
  • Fd9189
  • Fd9365
  • Fd9371
  • Fd9381
  • Fd9387
  • Fd9389
  • Fd9391
  • Fe9180
  • Fe9181
  • Fe9191
  • Fe9381
  • Fe9382
  • Fe9391
  • Fe9582
  • Ib9365
  • Ib93587lpr
  • Ib9371
  • Ib9381
  • Ib9387
  • Ib9389
  • Ib939
  • Ip9165
  • Ip9171
  • Ip9172
  • Ip9181
  • Ip9191
  • It9389
  • Ma9321
  • Ma9322
  • Ms9321
  • Ms9390
  • Tb9330
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *
  • *

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a vivotek fd8365 / / / / / / / /
a vivotek fd8365v2 / / / / / / / /
a vivotek fd9165 / / / / / / / /
a vivotek fd9171 / / / / / / / /
a vivotek fd9187 / / / / / / / /
a vivotek fd9189 / / / / / / / /
a vivotek fd9365 / / / / / / / /
a vivotek fd9371 / / / / / / / /
a vivotek fd9381 / / / / / / / /
a vivotek fd9387 / / / / / / / /
a vivotek fd9389 / / / / / / / /
a vivotek fd9391 / / / / / / / /
a vivotek fe9180 / / / / / / / /
a vivotek fe9181 / / / / / / / /
a vivotek fe9191 / / / / / / / /
a vivotek fe9381 / / / / / / / /
a vivotek fe9382 / / / / / / / /
a vivotek fe9391 / / / / / / / /
a vivotek fe9582 / / / / / / / /
a vivotek ib9365 / / / / / / / /
a vivotek ib93587lpr / / / / / / / /
a vivotek ib9371 / / / / / / / /
a vivotek ib9381 / / / / / / / /
a vivotek ib9387 / / / / / / / /
a vivotek ib9389 / / / / / / / /
a vivotek ib939 / / / / / / / /
a vivotek ip9165 / / / / / / / /
a vivotek ip9171 / / / / / / / /
a vivotek ip9172 / / / / / / / /
a vivotek ip9181 / / / / / / / /
a vivotek ip9191 / / / / / / / /
a vivotek it9389 / / / / / / / /
a vivotek ma9321 / / / / / / / /
a vivotek ma9322 / / / / / / / /
a vivotek ms9321 / / / / / / / /
a vivotek ms9390 / / / / / / / /
a vivotek tb9330 / / / / / / / /

CVSS Score

9.3 / 10

CVSS Data - 4.0

  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Attack Requirements: NONE
  • Privileges Required: NONE
  • User Interaction: NONE
  • Scope:
  • Confidentiality Impact: HIGH
  • Integrity Impact: HIGH
  • Availability Impact: HIGH
  • Exploit Maturity: PROOF_OF_CONCEPT
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber

    View Vector String

Timeline

Published: Jan. 13, 2026, 3:16 p.m.
Last Modified: Jan. 14, 2026, 4:26 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.