A critical authentication vulnerability affecting TP-Link’s VIGI surveillance camera lineup has been disclosed, enabling attackers on local networks to reset administrative credentials without authorization. Tracked as CVE-2026-0629, the flaw resides in the camera’s web interface password recovery function and carries a CVSS v4.0 score of 8.7, indicating high severity. The authentication bypass flaw stems from […]
The post TP-Link Vulnerability Allows Authentication Bypass Via Password Recovery Feature appeared first on Cyber Security News.
Read the original article: