CVE-2025-66051

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
References
Link Resource
https://cert.pl/posts/2026/01/CVE-2025-66049 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*

History

17 Jun 2026, 09:56

Type Values Removed Values Added
Summary
  • (es) La cámara Vivotek IP7137 con versión de firmware 0200a es vulnerable a salto de ruta. Es posible para un atacante autenticado acceder a recursos más allá del directorio webroot usando una solicitud HTTP directa. Debido a CVE-2025-66050, una contraseña para el panel de administración no está configurada por defecto. El proveedor no ha respondido a la CNA. Posiblemente todas las versiones de firmware están afectadas. Dado que el producto ha alcanzado la fase de Fin de Vida Útil, no se espera que se lance una solución.

14 Jan 2026, 17:49

Type Values Removed Values Added
References () https://cert.pl/posts/2026/01/CVE-2025-66049 - () https://cert.pl/posts/2026/01/CVE-2025-66049 - Third Party Advisory
First Time Vivotek ip7137
Vivotek ip7137 Firmware
Vivotek
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*

09 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 12:15

Updated : 2026-06-17 09:56


NVD link : CVE-2025-66051

Mitre link : CVE-2025-66051

CVE.ORG link : CVE-2025-66051


JSON object : View

Products Affected

vivotek

  • ip7137_firmware
  • ip7137
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')