Medium severity6.5NVD Advisory· Published May 28, 2020· Updated Jun 17, 2026
CVE-2020-11949
CVE-2020-11949
Description
testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.
Affected products
197- cpe:2.3:o:vivotek:fd836ba-ehvf2_firmware:*:*:*:*:*:*:*:*Range: <=0113b
- cpe:2.3:o:vivotek:fd9365-ehtv-a_firmware:*:*:*:*:*:*:*:*Range: <=0100m
- cpe:2.3:o:vivotek:fd9367-htv\(epoc\)_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:vivotek:fd9387-ehtv-a_firmware:*:*:*:*:*:*:*:*Range: <=0100m
- cpe:2.3:o:vivotek:ip9165-lpc\(i-cs_kit\)_firmware:*:*:*:*:*:*:*:*Range: <=0113d
- cpe:2.3:o:vivotek:ip9172-lpc\(freeway\)_firmware:*:*:*:*:*:*:*:*Range: <=0121d
- cpe:2.3:o:vivotek:sd9363-ehl-v2_firmware:*:*:*:*:*:*:*:*Range: <=0114a
- cpe:2.3:o:vivotek:sd9364-ehl-v2_firmware:*:*:*:*:*:*:*:*Range: <=0114a
- VIVOTEK/Network Camerasdescription
- Range: < XXXXX-VVTK-2.2002.xx.01x, < XXXXX-VVTK-0XXXX_Beta2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.