logo

Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All

ID: 99e47223-cd5e-50f6-a726-e77fcfc6eb3d

STIX ID: report--99e47223-cd5e-50f6-a726-e77fcfc6eb3d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

CERT Polska disclosed four severe vulnerabilities affecting legacy Vivotek IP7137 cameras: unauthenticated RTSP access exposing live feeds (CVE-2025-66049, CVSS 8.7), a default missing-admin-password condition permitting trivial admin access (CVE-2025-66050, CVSS 9.3), command injection via the system_ntplt parameter in /cgi-bin/admin/setparam.cgi (CVE-2025-66052, CVSS 8.6), and an authenticated path traversal allowing access beyond the webroot (CVE-2025-66051, CVSS 6.9); the device is EOL, the vendor did not respond to the CNA, and users are advised to remove or isolate affected cameras.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.