CVE-2018-14494: OS Command Injection
DISPUTED Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14494.
What is the severity of CVE-2018-14494?
The severity of CVE-2018-14494 is critical, with a severity value of 9.8.
What is the affected software?
The affected software is Vivotek FD8136 devices with firmware version 0301a.
What is the risk associated with this vulnerability?
This vulnerability allows remote command injection, which can lead to unauthorized access and control of the affected devices.
Are there any fixes available for this vulnerability?
No fixes are available as the vendor has clarified that this CVE is a historical vulnerability that does not apply to any current or recent Vivotek FD8136 devices.