Vivotek records
41 published records for vendor vivotek.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-121 Stack-based Buffer Overflow5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-787 Out-of-bounds Write2
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2017-9828No exploit | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which alvivotek · network camera ib8369 firmware · CWE-78 | Critical9.8 | — | 82.5% | Jun 23, 2017 |
51Plan | CVE-2017-9829No exploit | '/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers tvivotek · network camera ib8369 firmware · CWE-22 | High7.5 | — | 68.7% | Jun 23, 2017 |
51Plan | CVE-2013-1595Proof of concept | A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization headevivotek · pt7135 firmware · CWE-120 | Critical9.8 | — | 41.6% | Jan 24, 2020 |
41Plan | CVE-2013-1598Proof of concept | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binaryvivotek · pt7135 firmware · CWE-78 | High8.8 | — | 20.5% | Jan 24, 2020 |
40Plan | CVE-2018-14495No exploit | Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issuevivotek · fd8136 firmware · CWE-78 | Critical9.8 | — | 4.4% | Jul 10, 2019 |
40Plan | CVE-2018-14496No exploit | Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintfvivotek · fd8136 firmware · CWE-787 | Critical9.8 | — | 4.1% | Jul 10, 2019 |
40Plan | CVE-2018-14494No exploit | Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget.vivotek · fd8136 firmware · CWE-78 | Critical9.8 | — | 3.2% | Jul 10, 2019 |
40Plan | CVE-2019-14457No exploit | VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.vivotek · camera · CWE-787 | Critical9.8 | — | 2.6% | Sep 10, 2019 |
39Monitor | CVE-2008-4771Proof of concept | Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-4xem · vatctrl class · CWE-119 | Critical9.3 | — | 7.1% | Oct 28, 2008 |
39Monitor | CVE-2019-10256No exploit | An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.vivotek · camera | Critical9.8 | — | 1.3% | Sep 10, 2019 |
39Monitor | CVE-2024-26548No exploit | An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the uplovivotek · camera firmware | Critical9.8 | — | 1.1% | Feb 29, 2024 |
37Monitor | CVE-2025-66050No exploit | No password set for administrative account in Vivotek IP7137 camerasvivotek · ip7137 firmware · CWE-1393 | Critical9.3 | — | 0.4% | Jan 9, 2026 |
36Monitor | CVE-2024-7441No exploit | Vivotek SD9364 httpd read stack-based overflowvivotek · sd9364 firmware · CWE-121 | High8.7 | — | 8.1% | Aug 3, 2024 |
36Monitor | CVE-2018-14771No exploit | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.vivotek · camera | High8.8 | — | 3.0% | Sep 5, 2018 |
36Monitor | CVE-2018-14770No exploit | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/ovivotek · camera | High8.8 | — | 3.0% | Sep 5, 2018 |
36Monitor | CVE-2018-14768No exploit | Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to evivotek · camera | High8.8 | — | 2.9% | Aug 29, 2018 |
36Monitor | CVE-2020-11950No exploit | VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execuvivotek · cc9381-hv firmware · CWE-78 | High8.8 | — | 2.7% | May 28, 2020 |
35Monitor | CVE-2026-30650No exploit | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivvivotek · fd8136 firmware · CWE-120 | High8.8 | — | 0.9% | Jun 2, 2026 |
35Monitor | CVE-2026-30652No exploit | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras runnivivotek · fd8136 firmware · CWE-120 | High8.8 | — | 0.8% | Jun 2, 2026 |
35Monitor | CVE-2018-14769No exploit | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.vivotek · camera · CWE-352 | High8.8 | — | 0.5% | Sep 5, 2018 |
34Monitor | CVE-2025-66052No exploit | Command injection in Vivotek IP7137 camerasvivotek · ip7137 firmware · CWE-78 | High8.6 | — | 1.5% | Jan 9, 2026 |
34Monitor | CVE-2024-7439No exploit | Vivotek CC8160 httpd read stack-based overflowvivotek · cc8160 firmware · CWE-121 | High8.7 | — | 1.0% | Aug 3, 2024 |
34Monitor | CVE-2025-66049No exploit | Unprotected RTSP stream in Vivotek IP7137 camerasvivotek · ip7137 firmware · CWE-306 | High8.7 | — | 0.4% | Jan 9, 2026 |
33Monitor | CVE-2013-4985Proof of concept | Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video streamvivotek · ip7160 firmware · CWE-863 | High7.5 | — | 9.0% | Dec 27, 2019 |
32Monitor | CVE-2013-1594Proof of concept | An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd pavivotek · pt7135 firmware · CWE-200 | High7.5 | — | 7.3% | Jan 24, 2020 |
- CVE-2017-982864This week
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which al
CriticalCVSS 9.8No exploitEPSS 82%vivotek · network camera ib8369 firmwareJun 23, 2017
- CVE-2017-982951Plan
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers t
HighCVSS 7.5No exploitEPSS 69%vivotek · network camera ib8369 firmwareJun 23, 2017
- CVE-2013-159551Plan
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization heade
CriticalCVSS 9.8Proof of conceptEPSS 42%vivotek · pt7135 firmwareJan 24, 2020
- CVE-2013-159841Plan
A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary
HighCVSS 8.8Proof of conceptEPSS 20%vivotek · pt7135 firmwareJan 24, 2020
- CVE-2018-1449540Plan
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue
CriticalCVSS 9.8No exploitEPSS 4%vivotek · fd8136 firmwareJul 10, 2019
- CVE-2018-1449640Plan
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf
CriticalCVSS 9.8No exploitEPSS 4%vivotek · fd8136 firmwareJul 10, 2019
- CVE-2018-1449440Plan
Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget.
CriticalCVSS 9.8No exploitEPSS 3%vivotek · fd8136 firmwareJul 10, 2019
- CVE-2019-1445740Plan
VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.
CriticalCVSS 9.8No exploitEPSS 3%vivotek · cameraSep 10, 2019
- CVE-2008-477139Monitor
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-
CriticalCVSS 9.3Proof of conceptEPSS 7%4xem · vatctrl classOct 28, 2008
- CVE-2019-1025639Monitor
An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.
CriticalCVSS 9.8No exploitEPSS 1%vivotek · cameraSep 10, 2019
- CVE-2024-2654839Monitor
An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the uplo
CriticalCVSS 9.8No exploitEPSS 1%vivotek · camera firmwareFeb 29, 2024
- CVE-2025-6605037Monitor
No password set for administrative account in Vivotek IP7137 cameras
CriticalCVSS 9.3No exploitEPSS 0%vivotek · ip7137 firmwareJan 9, 2026
- CVE-2024-744136Monitor
Vivotek SD9364 httpd read stack-based overflow
HighCVSS 8.7No exploitEPSS 8%vivotek · sd9364 firmwareAug 3, 2024
- CVE-2018-1477136Monitor
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.
HighCVSS 8.8No exploitEPSS 3%vivotek · cameraSep 5, 2018
- CVE-2018-1477036Monitor
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/o
HighCVSS 8.8No exploitEPSS 3%vivotek · cameraSep 5, 2018
- CVE-2018-1476836Monitor
Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to e
HighCVSS 8.8No exploitEPSS 3%vivotek · cameraAug 29, 2018
- CVE-2020-1195036Monitor
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execu
HighCVSS 8.8No exploitEPSS 3%vivotek · cc9381-hv firmwareMay 28, 2020
- CVE-2026-3065035Monitor
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Viv
HighCVSS 8.8No exploitEPSS 1%vivotek · fd8136 firmwareJun 2, 2026
- CVE-2026-3065235Monitor
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras runni
HighCVSS 8.8No exploitEPSS 1%vivotek · fd8136 firmwareJun 2, 2026
- CVE-2018-1476935Monitor
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.
HighCVSS 8.8No exploitEPSS 0%vivotek · cameraSep 5, 2018
- CVE-2025-6605234Monitor
Command injection in Vivotek IP7137 cameras
HighCVSS 8.6No exploitEPSS 2%vivotek · ip7137 firmwareJan 9, 2026
- CVE-2024-743934Monitor
Vivotek CC8160 httpd read stack-based overflow
HighCVSS 8.7No exploitEPSS 1%vivotek · cc8160 firmwareAug 3, 2024
- CVE-2025-6604934Monitor
Unprotected RTSP stream in Vivotek IP7137 cameras
HighCVSS 8.7No exploitEPSS 0%vivotek · ip7137 firmwareJan 9, 2026
- CVE-2013-498533Monitor
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
HighCVSS 7.5Proof of conceptEPSS 9%vivotek · ip7160 firmwareDec 27, 2019
- CVE-2013-159432Monitor
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd pa
HighCVSS 7.5Proof of conceptEPSS 7%vivotek · pt7135 firmwareJan 24, 2020