Логотип exploitDog
bind:CVE-2025-66051
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66051

Количество 3

Количество 3

nvd логотип

CVE-2025-66051

3 месяца назад

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22q2-ww3p-hj7f

3 месяца назад

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-00868

3 месяца назад

Уязвимость микропрограммного обеспечения IP-камер Vivotek IP7137, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66051

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-22q2-ww3p-hj7f

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-00868

Уязвимость микропрограммного обеспечения IP-камер Vivotek IP7137, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.9
0%
Низкий
3 месяца назад

Уязвимостей на страницу