CVE-2025-66052

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
References
Link Resource
https://cert.pl/posts/2026/01/CVE-2025-66049 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*

History

17 Jun 2026, 09:56

Type Values Removed Values Added
Summary
  • (es) La cámara Vivotek IP7137 con la versión de firmware 0200a es vulnerable a inyección de comandos. El parámetro 'system_ntpIt' utilizado por el endpoint /cgi-bin/admin/setparam.cgi no se sanea correctamente, permitiendo que un usuario con privilegios administrativos realice un ataque. Debido a CVE-2025-66050, el acceso administrativo no está protegido por defecto. El proveedor no ha respondido a la CNA. Posiblemente todas las versiones de firmware están afectadas. Dado que el producto ha alcanzado la fase de Fin de Vida Útil, no se espera que se lance una solución.

14 Jan 2026, 17:50

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Vivotek ip7137
Vivotek ip7137 Firmware
Vivotek
CPE cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*
References () https://cert.pl/posts/2026/01/CVE-2025-66049 - () https://cert.pl/posts/2026/01/CVE-2025-66049 - Third Party Advisory

09 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 12:15

Updated : 2026-06-17 09:56


NVD link : CVE-2025-66052

Mitre link : CVE-2025-66052

CVE.ORG link : CVE-2025-66052


JSON object : View

Products Affected

vivotek

  • ip7137_firmware
  • ip7137
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')