CVE-2025-66050
published 2026-01-09CVE-2025-66050: Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.33%
25.2th percentile
Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need.
The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vivotek | ip7137 | — | — |
| vivotek | ip7137_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hj7-3vmc-gm54: Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection
ghsa_unreviewed·2026-01-09·CVSS 9.3
CVE-2025-66052 [CRITICAL] CWE-78 GHSA-6hj7-3vmc-gm54: Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection
Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,
The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
GHSA
GHSA-7h86-xp6g-v5h6: Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator
ghsa_unreviewed·2026-01-09
CVE-2025-66050 [CRITICAL] CWE-1393 GHSA-7h86-xp6g-v5h6: Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator
Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need.
The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
GHSA
GHSA-22q2-ww3p-hj7f: Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal
ghsa_unreviewed·2026-01-09·CVSS 9.3
CVE-2025-66051 [CRITICAL] CWE-22 GHSA-22q2-ww3p-hj7f: Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal
Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default.
The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-09
Published