Skip to content
IoT

CVE-2026-0629

8.7
High
EPSS 0.43%Jan 17, 2026

LAN-auth bypass lets attacker reset admin password on VIGI cameras.

common questions

Is CVE-2026-0629 being exploited?

Not confirmed. CVE-2026-0629 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.

How severe is CVE-2026-0629?

CVE-2026-0629 is rated High with a CVSS score of 8.7. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2026-0629?

Not known from our data. No patch reference has been recorded for CVE-2026-0629, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.

What does CVE-2026-0629 affect?

CVE-2026-0629 affects VIGI camera models (local web UI). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2026-0629?

Apply vendor patch ASAP; restrict LAN access to cameras.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
VIGI camera models (local web UI)
impact

Full admin access; attacker can change settings, exfiltrate data, disable security, and pivot within LAN.

action required

Patch when possible

affected versions
TP-Link Systems Inc. VIGI C230I Mini
  • affected< 2.1.0_Build_250701_Rel.47570n
TP-Link Systems Inc. VIGI C240 1.0
  • affected< 2.1.0_Build_250701_Rel.48425n
TP-Link Systems Inc. VIGI C250
  • affected< 2.1.0_Build_250702_Rel.54301n
TP-Link Systems Inc. VIGI C340 2.0
  • affected< 2.1.0_Build_250701_Rel.49304n
TP-Link Systems Inc. VIGI C340S
  • affected< 3.1.0_Build_250625_Rel.65381n
TP-Link Systems Inc. VIGI C340-W 2.x Series (C340-W 2.0/C340-W 2.20)
  • affected< 2.1.1_Build_250717_Rel.66528n
TP-Link Systems Inc. VIGI C440 2.0
  • affected< 2.1.0_Build_250701_Rel.49778n
TP-Link Systems Inc. VIGI C440-W 2.0
  • affected< 2.1.1_Build_250717_Rel.66632n
TP-Link Systems Inc. VIGI C540 2.0
  • affected< 2.1.0_Build_250701_Rel.50397n
TP-Link Systems Inc. VIGI C540-4G
  • affected< 2.2.0_Build_250826_Rel.56808n
TP-Link Systems Inc. VIGI C540S / EasyCam C540S
  • affected< 3.1.0_Build_250625_Rel.66601n
TP-Link Systems Inc. VIGI C540V
  • affected< 2.1.0_Build_250702_Rel.54300n
TP-Link Systems Inc. VIGI C540-W 2.0
  • affected< 2.1.1_Build_250717_Rel.67730n
TP-Link Systems Inc. VIGI Cx20I 1.0 Series (C220I 1.0/C320I 1.0/C420I 1.0)
  • affected< 2.1.0_Build_251014_Rel.58331n
TP-Link Systems Inc. VIGI Cx20I 1.20 Series (C220I 1.20/C320I 1.20/C420I 1.20)
  • affected< 2.1.0_Build_250701_Rel.44071n
TP-Link Systems Inc. VIGI Cx20 Series (C320/C420)
  • affected< 2.1.0_Build_250701_Rel.39597n
TP-Link Systems Inc. VIGI Cx30 1.0 Series (C230 1.0/C330 1.0/C430 1.0)
  • affected< 2.1.0_Build_250701_Rel.46796n
TP-Link Systems Inc. VIGI Cx30 1.20 Series (C230 1.20/C330 1.20/C430 1.20)
  • affected< 2.1.0_Build_250701_Rel.46796n
TP-Link Systems Inc. VIGI Cx30I 1.0 Series (C230I 1.0/C330I 1.0/C430I 1.0)
  • affected< 2.1.0_Build_250701_Rel.45506n
TP-Link Systems Inc. VIGI Cx30I 1.20 Series (C230I 1.20/C330I 1.20/C430I 1.20)
  • affected< 2.1.0_Build_250701_Rel.44555n
TP-Link Systems Inc. VIGI Cx40I 1.0 Series (C240I 1.0/C340I 1.0/C440I 1.0)
  • affected< 2.1.0_Build_250701_Rel.46003n
TP-Link Systems Inc. VIGI Cx40I 1.20 Series (C240I 1.20/C340I 1.20/C440I 1.20)
  • affected< 2.1.0_Build_250701_Rel.45041n
TP-Link Systems Inc. VIGI Cx45 Series (C345/C445)
  • affected< 3.1.0_Build_250820_Rel.57668n
TP-Link Systems Inc. VIGI Cx50 Series (C350/C450)
  • affected< 2.1.0_Build_250702_Rel.54294n
TP-Link Systems Inc. VIGI Cx55 Series (C355/C455)
  • affected< 3.1.0_Build_250820_Rel.58873n
TP-Link Systems Inc. VIGI Cx85 Series (C385/C485)
  • affected< 3.0.2_Build_250630_Rel.71279n
TP-Link Systems Inc. VIGI InSight S345-4G
  • affected< 2.1.0_Build_250725_Rel.36867n
TP-Link Systems Inc. VIGI InSight S655I
  • affected< 1.1.1_Build_250625_Rel.64224n
TP-Link Systems Inc. VIGI InSight Sx25 Series (S225/S325/S425)
  • affected< 1.1.0_Build_250630_Rel.39597n
TP-Link Systems Inc. VIGI InSight Sx45 Series (S245/S345/S445)
  • affected< 3.1.0_Build_250820_Rel.57668n
TP-Link Systems Inc. VIGI InSight Sx45ZI Series (S245ZI/S345ZI/S445ZI)
  • affected< 1.2.0_Build_250820_Rel.60930n
TP-Link Systems Inc. VIGI InSight Sx55 Series (S355/S455)
  • affected< 3.1.0_Build_250820_Rel.58873n
TP-Link Systems Inc. VIGI InSight Sx85PI Series (S385PI/S485PI)
  • affected< 1.2.0_Build_250827_Rel.66817n
TP-Link Systems Inc. VIGI InSight Sx85 Series (S285/S385)
  • affected< 3.0.2_Build_250630_Rel.71279n

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free