Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h86-xp6g-v5h6

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

EPSS

Процентиль: 17%
0.00054
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1393

Связанные уязвимости

CVSS3: 9.8
nvd
26 дней назад

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 9.8
fstec
27 дней назад

Уязвимость микропрограммного обеспечения IP-камер Vivotek IP7137, связанная с использованием пароля по умолчанию, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 17%
0.00054
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1393