CVE-2025-66052
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-09

Last updated on: 2026-01-09

Assigner: CERT.PL

Description
Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,Β  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-09
Last Modified
2026-01-09
Generated
2026-05-27
AI Q&A
2026-01-10
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
vivotek ip7137 From 0200a (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the Vivotek IP7137 camera with firmware version 0200a, where the parameter "system_ntpIt" used by the "/cgi-bin/admin/setparam.cgi" endpoint is not properly sanitized. This allows a user with administrative privileges to perform command injection attacks on the device. Because administrative access is not protected by default (related to CVE-2025-66050), an attacker with admin rights can exploit this flaw to execute arbitrary commands on the camera. The product is at its End-Of-Life stage, so no fix is expected.


How can this vulnerability impact me? :

An attacker with administrative privileges can exploit this vulnerability to execute arbitrary commands on the Vivotek IP7137 camera, potentially taking full control of the device. This can lead to unauthorized access, manipulation of camera functions, disruption of service, or use of the device as a foothold for further attacks within the network. Since administrative access is not protected by default, the risk of exploitation is higher. The lack of available patches increases the risk of long-term exposure.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

This vulnerability can be detected by checking for the presence of the vulnerable Vivotek IP7137 camera firmware version 0200a and by testing the /cgi-bin/admin/setparam.cgi endpoint for command injection via the "system_ntpIt" parameter. Since the vulnerability requires administrative privileges, verifying if administrative access is protected is also important. Network scanning tools can be used to identify devices running the vulnerable firmware. Specific commands are not provided in the resources. [1]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include restricting network access to the Vivotek IP7137 cameras, especially limiting access to trusted administrators only. Since the product is End-Of-Life and no patches are expected, disabling or isolating the device from untrusted networks is recommended. Additionally, ensure that administrative access is protected by strong authentication to prevent exploitation of the command injection vulnerability. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart