PT-2026-1856 · Vivotek · Vivotek Ip7137

Szymon Paszun

·

Publicado

2026-01-09

·

Atualizado

2026-01-09

·

CVE-2025-66052

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivotek IP7137 camera versions prior to 0200a
Description The Vivotek IP7137 camera is affected by a command injection issue. The /cgi-bin/admin/setparam.cgi API endpoint does not properly sanitize the system ntpIt parameter. This allows a user with administrative privileges to execute commands. Administrative access is not protected by default. As the product has reached its End-Of-Life phase, a fix is not expected.
Recommendations Update the firmware to a version newer than 0200a, if available. As a temporary workaround, restrict access to the /cgi-bin/admin/setparam.cgi endpoint. Avoid using the system ntpIt parameter in the affected API endpoint until the issue is resolved.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00867
CVE-2025-66052

Produtos afetados

Vivotek Ip7137