The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/01/CVE-2025-66049 |
|
Wed, 14 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek ip7137 Firmware
|
|
| CPEs | cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek ip7137 Firmware
|
|
| Metrics |
cvssV3_1
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek ip7137 |
|
| Vendors & Products |
Vivotek
Vivotek ip7137 |
Fri, 09 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default, The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released. | |
| Title | Command injection in Vivotek IP7137 cameras | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-09T12:51:10.558Z
Reserved: 2025-11-21T10:41:30.020Z
Link: CVE-2025-66052
Updated: 2026-01-09T12:51:02.918Z
Status : Analyzed
Published: 2026-01-09T12:15:53.883
Modified: 2026-01-14T17:50:09.087
Link: CVE-2025-66052
No data.
OpenCVE Enrichment
Updated: 2026-01-12T14:38:13Z