Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.
History

Fri, 16 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Description Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.
Title Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-01-16T17:38:48.262Z

Reserved: 2026-01-06T00:07:04.905Z

Link: CVE-2026-0629

cve-icon Vulnrichment

Updated: 2026-01-16T17:38:44.636Z

cve-icon NVD

Status : Received

Published: 2026-01-16T18:16:09.190

Modified: 2026-01-16T18:16:09.190

Link: CVE-2026-0629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.