Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,
The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/01/CVE-2025-66049 |
|
History
Fri, 09 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default, The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released. | |
| Title | Command injection in Vivotek IP7137 cameras | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-09T12:51:10.558Z
Reserved: 2025-11-21T10:41:30.020Z
Link: CVE-2025-66052
Updated: 2026-01-09T12:51:02.918Z
Status : Received
Published: 2026-01-09T12:15:53.883
Modified: 2026-01-09T12:15:53.883
Link: CVE-2025-66052
No data.
OpenCVE Enrichment
No data.