Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66051

Опубликовано: 09 янв. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
26 дней назад

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22