CVE-2026-35717

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:*
cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Un desbordamiento de búfer basado en pila en el binario export_language.cgi en el firmware VIVOTEK FD8136 FD8136-VVTK-0300a permite a atacantes remotos autenticados ejecutar código arbitrario como root a través de una solicitud POST manipulada al endpoint /cgi-bin/admin/export_language.cgi. El gestor pasa el valor Content-Length controlado por el atacante directamente a fread() como el tamaño de lectura en un búfer de pila de tamaño fijo de 0x60 bytes, sobrescribiendo el registro de enlace guardado. El binario se compila sin canarios de pila.

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://vivotek.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}

03 Jun 2026, 18:42

Type Values Removed Values Added
First Time Vivotek fd8136 Firmware
Vivotek fd8136
Vivotek
CPE cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:*
cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:*
References () http://vivotek.com - () http://vivotek.com - Product
References () https://github.com/xchg-rax-rax/vulnerability-research/tree/main/CVE-2026-35717 - () https://github.com/xchg-rax-rax/vulnerability-research/tree/main/CVE-2026-35717 - Third Party Advisory

03 Jun 2026, 14:16

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

02 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 14:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-35717

Mitre link : CVE-2026-35717

CVE.ORG link : CVE-2026-35717


JSON object : View

Products Affected

vivotek

  • fd8136
  • fd8136_firmware
CWE
CWE-121

Stack-based Buffer Overflow