Skip to main content

Vendor archive

vivotek CVEs

Beta · best-effort

41 CVEs tagged to vendor vivotek10 Critical, 18 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-35718

Published Jun 2, 2026

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device vi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35716

Published Jun 2, 2026

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30652

Published Jun 2, 2026

A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a.…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30650

Published Jun 2, 2026

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware ve…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30649

Published Jun 2, 2026

Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35717

Published Jun 2, 2026

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as roo…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66052

Published Jan 9, 2026

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized prop…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66051

Published Jan 9, 2026

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66050

Published Jan 9, 2026

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a pas…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66049

Published Jan 9, 2026

Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7443

Published Aug 3, 2024

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7442

Published Aug 3, 2024

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_fi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7440

Published Aug 3, 2024

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_fil…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26548

Published Feb 29, 2024

An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1598

Published Jan 24, 2020

A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1597

Published Jan 24, 2020

A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1595

Published Jan 24, 2020

A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1594

Published Jan 24, 2020

An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14458

Published Sep 18, 2019

VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2