VYPR
Vendor

Vivotek

Products
241
CVEs
44
Across products
103
Status
Private

Products

241
View all 241 products →

Recent CVEs

44
View all 44 CVEs →
  • CVE-2013-1595CriJan 24, 2020
    risk 0.70cvss 9.8epss 0.42

    A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.

  • CVE-2017-9828CriJun 23, 2017
    risk 0.70cvss 9.8epss 0.82

    '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK…

  • CVE-2025-66050CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.00

    Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all…

  • CVE-2024-26548CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.

  • CVE-2019-10256CriSep 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.

  • CVE-2019-14457CriSep 10, 2019
    risk 0.64cvss 9.8epss 0.03

    VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.

  • CVE-2018-14496CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.04

    Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a…

  • CVE-2018-14495CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.04

    Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or…

  • CVE-2018-14494CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.03

    Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or…

  • CVE-2026-22755CriJan 13, 2026
    risk 0.62cvss epss 0.20

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382,…

  • CVE-2013-1598HigJan 24, 2020
    risk 0.62cvss 8.8epss 0.20

    A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.

  • CVE-2025-12592CriNov 19, 2025
    risk 0.60cvss epss 0.00

    Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

  • CVE-2024-7441HigAug 3, 2024
    risk 0.58cvss 8.8epss 0.08

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow.…

  • CVE-2026-30652HigJun 2, 2026
    risk 0.57cvss 8.8epss 0.01

    A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.

  • CVE-2026-30650HigJun 2, 2026
    risk 0.57cvss 8.8epss 0.01

    A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as…

  • CVE-2024-7439HigAug 3, 2024
    risk 0.57cvss 8.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack…

  • CVE-2020-11950HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.03

    VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

  • CVE-2018-14771HigSep 5, 2018
    risk 0.57cvss 8.8epss 0.03

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.

  • CVE-2018-14770HigSep 5, 2018
    risk 0.57cvss 8.8epss 0.03

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/onvif/device_service).

  • CVE-2018-14769HigSep 5, 2018
    risk 0.57cvss 8.8epss 0.00

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.