Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h86-xp6g-v5h6

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

EPSS

Процентиль: 27%
0.0034
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1393

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 9.8
fstec
7 месяцев назад

Уязвимость микропрограммного обеспечения IP-камер Vivotek IP7137, связанная с использованием пароля по умолчанию, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 27%
0.0034
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1393