CVE-2026-26213: thingino-firmware Unauthenticated Command Injection in Captive Portal
Unauthenticated OS command injection in the WiFi captive portal API endpoint (api.cgi) of thingino-firmware allows any device on the camera's AP to execute arbitrary commands as root, achieving full device compromise.