← Back

Vivotek

vivotek

41 CVEs • 428 products

Products (428)

Click to collapse
Toggle
Camera
camera

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vivotek
1Pt7135 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.
1Vivotek
1Pt7135 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execut...Show more
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.Show less
1Vivotek
1Pt7135 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.
1Vivotek
3Ip7160 Firmware
Ip7361 FirmwareIp8332 Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
1Vivotek
1Camera
Jun 17, 2026
Sep 18, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.
1Vivotek
1Camera
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.
1Vivotek
1Camera
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.
1Vivotek
1Fd8136 Firmware
Nov 21, 2024
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as...Show more
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performanceShow less
1Vivotek
1Fd8136 Firmware
Nov 21, 2024
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and...Show more
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performanceShow less
1Vivotek
1Fd8136 Firmware
Nov 21, 2024
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a histori...Show more
Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmwareShow less
1Vivotek
1Camera
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
1Vivotek
1Camera
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.
1Vivotek
1Camera
Nov 21, 2024
Jan 3, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.
1Vivotek
1Camera
Nov 21, 2024
Sep 5, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.
1Vivotek
1Camera
Nov 21, 2024
Sep 5, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/onvif/device_service).
1Vivotek
1Camera
Nov 21, 2024
Sep 5, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.
1Vivotek
1Camera
Nov 21, 2024
Aug 29, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code.
1Vivotek
3Network Camera Fd8164 Firmware
Network Camera Fd816ba FirmwareNetwork Camera Ib8369 Firmware
May 13, 2026
Jun 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request cont...Show more
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected.Show less
1Vivotek
3Network Camera Fd8164 Firmware
Network Camera Fd816ba FirmwareNetwork Camera Ib8369 Firmware
May 13, 2026
Jun 23, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP re...Show more
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.Show less
34xem
D LinkVivotek
3Mpeg4 Shm Audio Control
Rtsp Mpeg4 Sp ControlVatctrl Class
Apr 23, 2026
Oct 28, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 S...Show more
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.Show less