Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · vivotek

vivotek

· 5 Critical

Total CVEs

35

Critical

5

Products

436

Search All CVEs →

35

Products (436)

camera11 CVEspt71355 CVEspt7135 firmware5 CVEsip7137 firmware4 CVEscc81604 CVEsip71374 CVEscc8160 firmware4 CVEsib8367a3 CVEsfd81363 CVEsfd8136 firmware3 CVEsib8367a firmware3 CVEscd8371-hnvf22 CVEscd8371-hnvf2 firmware2 CVEsfd8166a2 CVEsfd8166a-n2 CVEsfd8166a-n firmware2 CVEsfd8166a firmware2 CVEsfd8167a2 CVEsfd8167a firmware2 CVEsfd8169a2 CVEsfd8169a firmware2 CVEsfd816b-hf22 CVEsfd816b-hf2 firmware2 CVEsfd816b-ht2 CVEsfd816b-ht firmware2 CVEsfd816ba-hf22 CVEsfd816ba-hf2 firmware2 CVEsfd816ba-ht2 CVEsfd816ba-ht firmware2 CVEsfd816c-hf22 CVEsfd816c-hf2 firmware2 CVEsfd816ca-hf22 CVEsfd816ca-hf2 firmware2 CVEsfd8177-h2 CVEsfd8177-h firmware2 CVEsfd8177-ht2 CVEsfd8177-ht firmware2 CVEsfd8179-h2 CVEsfd8179-h firmware2 CVEsfd8182-f12 CVEsfd8182-f1 firmware2 CVEsfd8182-f22 CVEsfd8182-f2 firmware2 CVEsfd8182-t2 CVEsfd8182-t firmware2 CVEsfd8366-v2 CVEsfd8366-v firmware2 CVEsfd8367a-v2 CVEsfd8367a-v firmware2 CVEsfd8369a-v2 CVEsfd8369a-v firmware2 CVEsfd836b-ehtv2 CVEsfd836b-ehtv firmware2 CVEsfd836b-ehvf22 CVEsfd836b-ehvf2 firmware2 CVEsfd836b-htv2 CVEsfd836b-htv firmware2 CVEsfd836b-hvf22 CVEsfd836b-hvf2 firmware2 CVEsfd836ba-ehtv2 CVEsfd836ba-ehtv firmware2 CVEsfd836ba-ehvf22 CVEsfd836ba-ehvf2 firmware2 CVEsfd836ba-htv2 CVEsfd836ba-htv firmware2 CVEsfd836ba-hvf22 CVEsfd836ba-hvf2 firmware2 CVEsfd8377-ehtv2 CVEsfd8377-ehtv firmware2 CVEsfd8377-htv2 CVEsfd8377-htv firmware2 CVEsfd8377-hv2 CVEsfd8377-hv firmware2 CVEsfd8379-hv2 CVEsfd8379-hv firmware2 CVEsfd8382-etv2 CVEsfd8382-etv firmware2 CVEsfd8382-evf22 CVEsfd8382-evf2 firmware2 CVEsfd8382-tv2 CVEsfd8382-tv firmware2 CVEsfd8382-vf22 CVEsfd8382-vf2 firmware2 CVEsfd9165-ht2 CVEsfd9165-ht-a2 CVEsfd9165-ht-a firmware2 CVEsfd9165-ht firmware2 CVEsfd9166-hn2 CVEsfd9166-hn firmware2 CVEsfd9167-h2 CVEsfd9167-h firmware2 CVEsfd9167-ht2 CVEsfd9167-ht firmware2 CVEsfd9171-ht2 CVEsfd9171-ht firmware2 CVEsfd9181-ht2 CVEsfd9181-ht firmware2 CVEsfd9187-h2 CVEsfd9187-h firmware2 CVEsfd9187-ht2 CVEsfd9187-ht-a2 CVEsfd9187-ht-a firmware2 CVEsfd9187-ht firmware2 CVEsfd9189-h2 CVEsfd9189-h firmware2 CVEsfd9189-hm2 CVEsfd9189-hm firmware2 CVEsfd9189-ht2 CVEsfd9189-ht firmware2 CVEsfd9360-h2 CVEsfd9360-h firmware2 CVEsfd9365-ehtv2 CVEsfd9365-ehtv-a2 CVEsfd9365-ehtv-a firmware2 CVEsfd9365-ehtv firmware2 CVEsfd9365-htv2 CVEsfd9365-htv-a2 CVEsfd9365-htv-a firmware2 CVEsfd9365-htv firmware2 CVEsfd9365-htvl2 CVEsfd9365-htvl firmware2 CVEsfd9366-hv2 CVEsfd9366-hv firmware2 CVEsfd9367-ehtv2 CVEsfd9367-ehtv firmware2 CVEsfd9367-htv2 CVEsfd9367-htv\(epoc\)2 CVEsfd9367-htv\(epoc\) firmware2 CVEsfd9367-htv firmware2 CVEsfd9367-hv2 CVEsfd9367-hv firmware2 CVEsfd9368-htv2 CVEsfd9368-htv firmware2 CVEsvs8100-v2 firmware2 CVEscc8160\(hs\)2 CVEscc8160\(hs\) firmware2 CVEscc8370-hv2 CVEscc8370-hv firmware2 CVEscc8371-hv2 CVEscc8371-hv firmware2 CVEscc9381-hv2 CVEscc9381-hv firmware2 CVEscd8371-hntv2 CVEscd8371-hntv firmware2 CVEsnetwork camera fd81642 CVEsnetwork camera fd8164 firmware2 CVEsnetwork camera fd816ba2 CVEsnetwork camera fd816ba firmware2 CVEsnetwork camera ib83692 CVEsnetwork camera ib8369 firmware2 CVEssd9161-h2 CVEssd9161-h firmware2 CVEssd9361-ehl2 CVEssd9361-ehl firmware2 CVEssd9362-eh2 CVEssd9362-eh-v22 CVEssd9362-eh-v2 firmware2 CVEssd9362-eh firmware2 CVEssd9362-ehl2 CVEssd9362-ehl firmware2 CVEssd9363-ehl2 CVEssd9363-ehl-v22 CVEssd9363-ehl-v2 firmware2 CVEssd9363-ehl firmware2 CVEssd93642 CVEssd9364-eh2 CVEssd9364-eh-v22 CVEssd9364-eh-v2 firmware2 CVEssd9364-eh firmware2 CVEssd9364-ehl2 CVEssd9364-ehl-v22 CVEssd9364-ehl-v2 firmware2 CVEssd9364-ehl firmware2 CVEssd9364 firmware2 CVEssd9365-ehl2 CVEssd9365-ehl firmware2 CVEssd9366-eh2 CVEssd9366-eh-v22 CVEssd9366-eh-v2 firmware2 CVEssd9366-eh firmware2 CVEssd9366-ehl2 CVEssd9366-ehl firmware2 CVEstb9330-e2 CVEstb9330-e firmware2 CVEstb9331-e2 CVEstb9331-e firmware2 CVEsvc81012 CVEsvc8101 firmware2 CVEsvs8100-v22 CVEsfd9380-h2 CVEsfd9380-h firmware2 CVEsfd9387-ehtv2 CVEsfd9387-ehtv-a2 CVEsfd9387-ehtv-a firmware2 CVEsfd9387-ehtv firmware2 CVEsfd9387-ehv2 CVEsfd9387-ehv firmware2 CVEsfd9387-htv2 CVEsfd9387-htv-a2 CVEsfd9387-htv-a firmware2 CVEsfd9387-htv firmware2 CVEsfd9387-hv2 CVEsfd9387-hv firmware2 CVEsfd9388-htv2 CVEsfd9388-htv firmware2 CVEsfd9389-ehmv2 CVEsfd9389-ehmv firmware2 CVEsfd9389-ehtv2 CVEsfd9389-ehtv firmware2 CVEsfd9389-ehv2 CVEsfd9389-ehv firmware2 CVEsfd9389-hmv2 CVEsfd9389-hmv firmware2 CVEsfd9389-htv2 CVEsfd9389-htv firmware2 CVEsfd9389-hv2 CVEsfd9389-hv firmware2 CVEsfd9391-ehtv2 CVEsfd9391-ehtv firmware2 CVEsfe9180-h2 CVEsfe9180-h firmware2 CVEsfe9181-h2 CVEsfe9181-h firmware2 CVEsfe9182-h2 CVEsfe9182-h firmware2 CVEsfe91912 CVEsfe9191 firmware2 CVEsfe9380-hv2 CVEsfe9380-hv firmware2 CVEsfe9381-ehv2 CVEsfe9381-ehv firmware2 CVEsfe9382-ehv2 CVEsfe9382-ehv firmware2 CVEsfe9391-ev2 CVEsfe9391-ev firmware2 CVEsfe9582-ehnv2 CVEsfe9582-ehnv firmware2 CVEsib83602 CVEsib8360-w2 CVEsib8360-w firmware2 CVEsib8360 firmware2 CVEsib8369a2 CVEsib8369a firmware2 CVEsib836b-ehf32 CVEsib836b-ehf3 firmware2 CVEsib836b-eht2 CVEsib836b-eht firmware2 CVEsib836b-hf32 CVEsib836b-hf3 firmware2 CVEsib836b-hrf32 CVEsib836b-hrf3 firmware2 CVEsib836b-ht2 CVEsib836b-ht firmware2 CVEsib836ba-ehf32 CVEsib836ba-ehf3 firmware2 CVEsib836ba-eht2 CVEsib836ba-eht firmware2 CVEsib836ba-hf32 CVEsib836ba-hf3 firmware2 CVEsib836ba-ht2 CVEsib836ba-ht firmware2 CVEsib8377-eht2 CVEsib8377-eht firmware2 CVEsib8377-h2 CVEsib8377-h firmware2 CVEsib8377-ht2 CVEsib8377-ht firmware2 CVEsib8382-ef32 CVEsib8382-ef3 firmware2 CVEsib8382-et2 CVEsib8382-et firmware2 CVEsib8382-f32 CVEsib8382-f3 firmware2 CVEsib8382-t2 CVEsib8382-t firmware2 CVEsib9360-h2 CVEsib9360-h firmware2 CVEsib9365-eht2 CVEsib9365-eht-a2 CVEsib9365-eht-a firmware2 CVEsib9365-eht firmware2 CVEsib9365-ht2 CVEsib9365-ht-a2 CVEsib9365-ht-a firmware2 CVEsib9365-ht firmware2 CVEsib9367-eh2 CVEsib9367-eh firmware2 CVEsib9367-eht2 CVEsib9367-eht firmware2 CVEsib9367-h2 CVEsib9367-h firmware2 CVEsib9367-ht2 CVEsib9367-ht firmware2 CVEsib9368-ht2 CVEsib9368-ht firmware2 CVEsib9380-h2 CVEsib9380-h firmware2 CVEsib9387-eh2 CVEsib9387-eh firmware2 CVEsib9387-eht2 CVEsib9387-eht-a2 CVEsib9387-eht-a firmware2 CVEsib9387-eht firmware2 CVEsib9387-h2 CVEsib9387-h firmware2 CVEsib9387-ht2 CVEsib9387-ht-a2 CVEsib9387-ht-a firmware2 CVEsib9387-ht firmware2 CVEsib9388-ht2 CVEsib9388-ht firmware2 CVEsib9389-eh2 CVEsib9389-eh firmware2 CVEsib9389-ehm2 CVEsib9389-ehm firmware2 CVEsib9389-eht2 CVEsib9389-eht firmware2 CVEsib9389-h2 CVEsib9389-h firmware2 CVEsib9389-hm2 CVEsib9389-hm firmware2 CVEsib9389-ht2 CVEsib9389-ht firmware2 CVEsib9391-eht2 CVEsib9391-eht firmware2 CVEsip81602 CVEsip8160-w2 CVEsip8160-w firmware2 CVEsip8160 firmware2 CVEsip81662 CVEsip8166 firmware2 CVEsip9164-ht2 CVEsip9164-ht firmware2 CVEsip9164-lpc2 CVEsip9164-lpc firmware2 CVEsip9165-hp2 CVEsip9165-hp firmware2 CVEsip9165-ht2 CVEsip9165-ht firmware2 CVEsip9165-lpc2 CVEsip9165-lpc\(i-cs kit\)2 CVEsip9165-lpc\(i-cs kit\) firmware2 CVEsip9165-lpc firmware2 CVEsip9167-hp2 CVEsip9167-hp firmware2 CVEsip9167-ht2 CVEsip9167-ht firmware2 CVEsip9171-hp2 CVEsip9171-hp firmware2 CVEsip9181-h2 CVEsip9181-h firmware2 CVEsip9191-hp2 CVEsip9191-hp firmware2 CVEsip9191-ht2 CVEsip9191-ht firmware2 CVEsit9360-h2 CVEsit9360-h firmware2 CVEsit9380-h2 CVEsit9380-h firmware2 CVEsit9388-ht2 CVEsit9388-ht firmware2 CVEsit9389-h2 CVEsit9389-h firmware2 CVEsit9389-ht2 CVEsit9389-ht firmware2 CVEsiz9361-eh2 CVEsiz9361-eh firmware2 CVEsma9321-ehtv2 CVEsma9321-ehtv firmware2 CVEsma9322-ehtv2 CVEsma9322-ehtv firmware2 CVEsmd8563-deh2 CVEsmd8563-deh firmware2 CVEsmd8563-eh2 CVEsmd8563-eh firmware2 CVEsmd8564-eh2 CVEsmd8564-eh firmware2 CVEsmd8565-n2 CVEsmd8565-n firmware2 CVEsmd9560-dh2 CVEsmd9560-dh firmware2 CVEsmd9560-h2 CVEsmd9560-h firmware2 CVEsmd9561-h2 CVEsmd9561-h firmware2 CVEsmd9581-h2 CVEsmd9581-h firmware2 CVEsms9321-ehv2 CVEsms9321-ehv firmware2 CVEsms9390-hv2 CVEsms9390-hv firmware2 CVEsfd9371-ehtv1 CVEsfd9371-ehtv firmware1 CVEsip9172-lpc firmware1 CVEscamera firmware1 CVEsfd9381-\(e\)htv1 CVEsfd9381-\(e\)htv firmware1 CVEsfd9381-ehtv1 CVEsfd9381-ehtv firmware1 CVEssd9374-ehl1 CVEsmjpegcontrol1 CVEssd9374-ehl\(x\)1 CVEsib9371-\(e\)ht1 CVEsib8379-h1 CVEsib8379-h firmware1 CVEsib9371-\(e\)ht firmware1 CVEsib9371-eht1 CVEsib9371-eht firmware1 CVEsip83321 CVEsip8332 firmware1 CVEsib9381-\(e\)ht1 CVEsib8382-rf31 CVEsfd9371-\(e\)htv firmware1 CVEsfd9371-\(e\)htv1 CVEsib8382-rf3 firmware1 CVEsib8382-rt1 CVEsib8382-rt firmware1 CVEsib9381-\(e\)ht firmware1 CVEsib9381-eht1 CVEsib9381-eht firmware1 CVEssd9374-ehl\(x\) firmware1 CVEsfd8167a-s firmware1 CVEsfd8167a-s1 CVEsrtsp mpeg4 sp control1 CVEssd9374-ehl firmware1 CVEsip9172-lpc1 CVEsip9172-lpc\(freeway\)1 CVEsfe81821 CVEsfe8182 firmware1 CVEsfd8169a-s firmware1 CVEsfd8169a-s1 CVEsip71601 CVEsip7160 firmware1 CVEsip73611 CVEsip7361 firmware1 CVEsip9172-lpc\(freeway\) firmware1 CVEs

Recent Vulnerabilities

View all 35
CVE-2025-66052HIGH 7.2

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVE-2025-66051MEDIUM 6.5

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVE-2025-66050CRITICAL 9.8

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVE-2025-66049HIGH 7.5

Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security.  The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVE-2024-7443MEDIUM 6.3

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-273528. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

CVE-2024-7442MEDIUM 6.3

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-273527. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

CVE-2024-7441HIGH 8.8

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273526 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

CVE-2024-7440MEDIUM 6.3

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It is possible to initiate the attack remotely. The identifier VDB-273525 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

CVE-2024-7439HIGH 8.8

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273524. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

CVE-2024-26548CRITICAL 9.8

An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.

CVE-2020-11950HIGH 8.8

VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

CVE-2020-11949MEDIUM 6.5

testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.

CVE-2013-1598HIGH 8.8

A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.

CVE-2013-1597MEDIUM 6.5

A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.

CVE-2013-1596MEDIUM 5.3

An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.

CVE-2013-1595CRITICAL 9.8

A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.

CVE-2013-1594HIGH 7.5

An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.

CVE-2013-4985HIGH 7.5

Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

CVE-2019-14458HIGH 7.5

VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.

CVE-2019-10256CRITICAL 9.8

An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.

CVE-2019-14457CRITICAL 9.8

VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.

CVE-2018-14496

Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

CVE-2018-14495

Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

CVE-2018-14494

Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware

CVE-2018-18244

Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.