Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security. | |
| Title | Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-01-16T17:38:48.262Z
Reserved: 2026-01-06T00:07:04.905Z
Link: CVE-2026-0629
Updated: 2026-01-16T17:38:44.636Z
Status : Received
Published: 2026-01-16T18:16:09.190
Modified: 2026-01-16T18:16:09.190
Link: CVE-2026-0629
No data.
OpenCVE Enrichment
No data.