CVE-2026-0629
LAN-auth bypass lets attacker reset admin password on VIGI cameras.
Is CVE-2026-0629 being exploited?
Not confirmed. CVE-2026-0629 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.
How severe is CVE-2026-0629?
CVE-2026-0629 is rated High with a CVSS score of 8.7. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-0629?
Not known from our data. No patch reference has been recorded for CVE-2026-0629, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.
What does CVE-2026-0629 affect?
CVE-2026-0629 affects VIGI camera models (local web UI). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-0629?
Apply vendor patch ASAP; restrict LAN access to cameras.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Full admin access; attacker can change settings, exfiltrate data, disable security, and pivot within LAN.
Patch when possible
- affected< 2.1.0_Build_250701_Rel.47570n
- affected< 2.1.0_Build_250701_Rel.48425n
- affected< 2.1.0_Build_250702_Rel.54301n
- affected< 2.1.0_Build_250701_Rel.49304n
- affected< 3.1.0_Build_250625_Rel.65381n
- affected< 2.1.1_Build_250717_Rel.66528n
- affected< 2.1.0_Build_250701_Rel.49778n
- affected< 2.1.1_Build_250717_Rel.66632n
- affected< 2.1.0_Build_250701_Rel.50397n
- affected< 2.2.0_Build_250826_Rel.56808n
- affected< 3.1.0_Build_250625_Rel.66601n
- affected< 2.1.0_Build_250702_Rel.54300n
- affected< 2.1.1_Build_250717_Rel.67730n
- affected< 2.1.0_Build_251014_Rel.58331n
- affected< 2.1.0_Build_250701_Rel.44071n
- affected< 2.1.0_Build_250701_Rel.39597n
- affected< 2.1.0_Build_250701_Rel.46796n
- affected< 2.1.0_Build_250701_Rel.46796n
- affected< 2.1.0_Build_250701_Rel.45506n
- affected< 2.1.0_Build_250701_Rel.44555n
- affected< 2.1.0_Build_250701_Rel.46003n
- affected< 2.1.0_Build_250701_Rel.45041n
- affected< 3.1.0_Build_250820_Rel.57668n
- affected< 2.1.0_Build_250702_Rel.54294n
- affected< 3.1.0_Build_250820_Rel.58873n
- affected< 3.0.2_Build_250630_Rel.71279n
- affected< 2.1.0_Build_250725_Rel.36867n
- affected< 1.1.1_Build_250625_Rel.64224n
- affected< 1.1.0_Build_250630_Rel.39597n
- affected< 3.1.0_Build_250820_Rel.57668n
- affected< 1.2.0_Build_250820_Rel.60930n
- affected< 3.1.0_Build_250820_Rel.58873n
- affected< 1.2.0_Build_250827_Rel.66817n
- affected< 3.0.2_Build_250630_Rel.71279n
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.