CVE-2025-66052: Command injection in Vivotek IP7137 cameras
Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "systemntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default, The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66052?
CVE-2025-66052 is considered a high-severity vulnerability due to the potential for command injection and unauthorized administrative actions.
How do I fix CVE-2025-66052?
To fix CVE-2025-66052, upgrade the firmware of your Vivotek IP7137 camera to a version that addresses the command injection vulnerability.
Who is affected by CVE-2025-66052?
CVE-2025-66052 affects users of the Vivotek IP7137 camera running firmware version 0200a.
What type of vulnerability is CVE-2025-66052?
CVE-2025-66052 is a command injection vulnerability that occurs due to improper input sanitization.
What are the consequences of exploiting CVE-2025-66052?
Exploitation of CVE-2025-66052 could allow an attacker with administrative access to execute arbitrary commands on the Vivotek IP7137 camera.