CVE-2026-35716: Buffer Overflow
A stack-based buffer overflow in the motionprivacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmdprofile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35716?
The severity of CVE-2026-35716 is classified as medium with a CVSS score of 6.3.
How do I fix CVE-2026-35716?
To mitigate CVE-2026-35716, it is recommended to update the VIVOTEK FD8136 firmware to the latest version provided by the manufacturer.
What is the impact of CVE-2026-35716?
CVE-2026-35716 allows authenticated remote attackers to execute arbitrary code as root, potentially compromising the device.
What causes CVE-2026-35716?
CVE-2026-35716 is caused by a stack-based buffer overflow in the motion_privacy.cgi binary during the handling of an oversized n1 parameter.
Which devices are affected by CVE-2026-35716?
CVE-2026-35716 affects VIVOTEK FD8136 firmware, specifically version FD8136-VVTK-0300a.