CVE-2026-35716

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Un desbordamiento de búfer basado en pila en el binario motion_privacy.cgi en el firmware VIVOTEK FD8136 FD8136-VVTK-0300a permite a atacantes remotos autenticados ejecutar código arbitrario como root a través de un parámetro n1 sobredimensionado en una solicitud POST al endpoint /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, o /cgi-bin/admin/setmd_profile.cgi (todos enlaces simbólicos al mismo binario). El valor del parámetro se copia en un búfer de pila de tamaño fijo de 0xa4 bytes sin comprobación de límites, sobrescribiendo el registro de enlace guardado. El binario se compila sin canarios de pila.

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://vivotek.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}

03 Jun 2026, 18:40

Type Values Removed Values Added
First Time Vivotek fd8136 Firmware
Vivotek fd8136
Vivotek
References () http://vivotek.com - () http://vivotek.com - Product
References () https://github.com/xchg-rax-rax/vulnerability-research/tree/main/CVE-2026-35716 - () https://github.com/xchg-rax-rax/vulnerability-research/tree/main/CVE-2026-35716 - Third Party Advisory
CPE cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:*
cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:*

03 Jun 2026, 14:16

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

02 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 16:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-35716

Mitre link : CVE-2026-35716

CVE.ORG link : CVE-2026-35716


JSON object : View

Products Affected

vivotek

  • fd8136
  • fd8136_firmware
CWE
CWE-121

Stack-based Buffer Overflow