CVE-2026-0629

Administrative takeover via client-side reset state

Published Jan 16, 2026 · Updated Jan 16, 2026

Authentication bypass in TP-Link VIGI camera web apps allows remote attackers on the LAN to reset the administrator password. The password-recovery flow trusts attacker-manipulated client-side state and completes the reset without verifying the recovery request. No prior credentials or user interaction are required, but the attacker must reach the camera from the same LAN; success grants full administrative control over device configuration.

CVSS severity8.7
High
EPSS probability0.43%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Authentication bypass in TP-Link VIGI camera web apps allows remote attackers on the LAN to reset the administrator password. The password-recovery flow trusts attacker-manipulated client-side state and completes the reset without verifying the recovery request. No prior credentials or user interaction are required, but the attacker must reach the camera from the same LAN; success grants full administrative control over device configuration.

The record

CVE
CVE-2026-0629
Published
Jan 16, 2026
Updated
Jan 16, 2026
Vendor
TP-Link Systems Inc.
Product
VIGI C340-W
Classifications
CWE-287, T1098
Attack vector
adjacent
Privileges
unauthenticated

Timeline

How it unfolded

  1. Jan 16, 2026CVE publishedPublication date reported by the CVE source.
  2. Jan 16, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <2.1.1_Build_250717_Rel.66528n

What conditions does exploitation require?

Attack vectoradjacent
Required privilegesunauthenticated

What is affected?

TP-Link Systems Inc. · VIGI C340-Wversion=0 <2.1.1_Build_250717_Rel.66528n
TP-Link Systems Inc. · VIGI Cx50 Seriesversion=0 <2.1.0_Build_250702_Rel.54294n
TP-Link Systems Inc. · VIGI C440-Wversion=0 <2.1.1_Build_250717_Rel.66632n
TP-Link Systems Inc. · VIGI InSight Sx45ZI Seriesversion=0 <1.2.0_Build_250820_Rel.60930n
TP-Link Systems Inc. · VIGI C540Sversion=0 <3.1.0_Build_250625_Rel.66601n
TP-Link Systems Inc. · VIGI Cx85 Seriesversion=0 <3.0.2_Build_250630_Rel.71279n
TP-Link Systems Inc. · VIGI C540-4Gversion=0 <2.2.0_Build_250826_Rel.56808n
TP-Link Systems Inc. · VIGI C340 2.0version=0 <2.1.0_Build_250701_Rel.49304n
TP-Link Systems Inc. · VIGI C240 1.0version=0 <2.1.0_Build_250701_Rel.48425n
TP-Link Systems Inc. · VIGI Cx45 Seriesversion=0 <3.1.0_Build_250820_Rel.57668n
TP-Link Systems Inc. · VIGI C540version=0 <2.1.0_Build_250701_Rel.50397n
TP-Link Systems Inc. · VIGI C250version=0 <2.1.0_Build_250702_Rel.54301n
TP-Link Systems Inc. · VIGI InSight Sx55 Seriesversion=0 <3.1.0_Build_250820_Rel.58873n
TP-Link Systems Inc. · VIGI InSight Sx45 Seriesversion=0 <3.1.0_Build_250820_Rel.57668n
TP-Link Systems Inc. · VIGI InSight Sx25 Seriesversion=0 <1.1.0_Build_250630_Rel.39597n
TP-Link Systems Inc. · VIGI InSight Sx85PI Seriesversion=0 <1.2.0_Build_250827_Rel.66817n
TP-Link Systems Inc. · VIGI C340Sversion=0 <3.1.0_Build_250625_Rel.65381n
TP-Link Systems Inc. · VIGI Cx30version=0 <2.1.0_Build_250701_Rel.46796n
TP-Link Systems Inc. · VIGI Cx20 Seriesversion=0 <2.1.0_Build_250701_Rel.39597n
TP-Link Systems Inc. · VIGI Cx40Iversion=0 <2.1.0_Build_250701_Rel.45041n; version=0 <2.1.0_Build_250701_Rel.46003n
TP-Link Systems Inc. · VIGI InSight S345-4Gversion=0 <2.1.0_Build_250725_Rel.36867n
TP-Link Systems Inc. · VIGI Cx20Iversion=0 <2.1.0_Build_250701_Rel.44071n; version=0 <2.1.0_Build_251014_Rel.58331n
TP-Link Systems Inc. · VIGI C440 2.0version=0 <2.1.0_Build_250701_Rel.49778n
TP-Link Systems Inc. · VIGI InSight Sx85 Seriesversion=0 <3.0.2_Build_250630_Rel.71279n
TP-Link Systems Inc. · VIGI C540-Wversion=0 <2.1.1_Build_250717_Rel.67730n
TP-Link Systems Inc. · VIGI Cx55 Seriesversion=0 <3.1.0_Build_250820_Rel.58873n
TP-Link Systems Inc. · VIGI C540Vversion=0 <2.1.0_Build_250702_Rel.54300n
TP-Link Systems Inc. · VIGI Cx30Iversion=0 <2.1.0_Build_250701_Rel.44555n
TP-Link Systems Inc. · VIGI Cx30I Seriesversion=0 <2.1.0_Build_250701_Rel.45506n
TP-Link Systems Inc. · VIGI C230I Miniversion=0 <2.1.0_Build_250701_Rel.47570n
TP-Link Systems Inc. · VIGI InSight S655Iversion=0 <1.1.1_Build_250625_Rel.64224n

Published CVSS scores

8.7TPLinkCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectoradjacent
Privilegesunauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-287Improper Authentication
T1098Account Manipulation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo