The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/01/CVE-2025-66049 |
|
Wed, 14 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek ip7137 Firmware
|
|
| CPEs | cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek ip7137 Firmware
|
|
| Metrics |
cvssV3_1
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek ip7137 |
|
| Vendors & Products |
Vivotek
Vivotek ip7137 |
Fri, 09 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released. | |
| Title | Path traversal in Vivotek IP7137 cameras | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-09T14:07:13.457Z
Reserved: 2025-11-21T10:41:30.020Z
Link: CVE-2025-66051
Updated: 2026-01-09T14:07:03.116Z
Status : Analyzed
Published: 2026-01-09T12:15:53.740
Modified: 2026-01-14T17:49:09.330
Link: CVE-2025-66051
No data.
OpenCVE Enrichment
Updated: 2026-01-12T14:38:16Z