PT-2026-1856 · Vivotek · Vivotek Ip7137

·

CVE-2025-66052

·

Published

2026-01-09

·

Updated

2026-01-09

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vivotek IP7137 camera versions prior to 0200a
Description The Vivotek IP7137 camera is affected by a command injection issue. The /cgi-bin/admin/setparam.cgi API endpoint does not properly sanitize the system ntpIt parameter. This allows a user with administrative privileges to execute commands. Administrative access is not protected by default. As the product has reached its End-Of-Life phase, a fix is not expected.
Recommendations Update the firmware to a version newer than 0200a, if available. As a temporary workaround, restrict access to the /cgi-bin/admin/setparam.cgi endpoint. Avoid using the system ntpIt parameter in the affected API endpoint until the issue is resolved.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00867
CVE-2025-66052

Affected Products

Vivotek Ip7137