Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-16 18:16
Updated : 2026-01-26 15:05
NVD link : CVE-2026-0629
Mitre link : CVE-2026-0629
CVE.ORG link : CVE-2026-0629
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
