Description
Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component
Published: 2026-06-02
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic buffer overflow in the set_getparam.cgi component of VIVOTEK INC FD8136-VVTK-0300a firmware. An attacker who can reach the device’s web interface can supply an oversized payload that overwrites memory and gains arbitrary code execution, directly compromising the confidentiality, integrity, and availability of the device and any systems it connects to.

Affected Systems

VIVOTEK’s FD8136-VVTK-0300a camera firmware is affected. No specific firmware revisions are listed, so any deployment of this product model should be reviewed for the presence of the set_getparam.cgi component. Users should verify the firmware version and consult VIVOTEK documentation.

Risk and Exploitability

The risk is high because the flaw enables remote code execution via a web interface that is typically reachable over the network. The CVSS score of 7.3 indicates a high severity, and the EPSS score is less than 1%, suggesting a low likelihood but still possible exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the lack of mitigation data does not reduce the severity implied by the CVE description. Attackers can exploit this remotely without user interaction, making the window of opportunity large. Organizations should treat this as a critical threat.

Generated by OpenCVE AI on June 3, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from VIVOTEK that corrects the set_getparam.cgi buffer overflow, thereby fixing the underlying buffer overflow issue.
  • If an update is unavailable or not yet applied, restrict external access to the device’s web interface by placing the camera behind a firewall or VLAN, allowing only trusted management networks.
  • Where possible, disable or block the set_getparam.cgi service if it is not required for operation.

Generated by OpenCVE AI on June 3, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Vivotek fd8136
Vivotek fd8136 Firmware
CPEs cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:*
cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:*
Vendors & Products Vivotek fd8136
Vivotek fd8136 Firmware

Wed, 03 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in VIVOTEK Camera Firmware Allows Remote Code Execution
Weaknesses CWE-119

Wed, 03 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Vivotek
Vivotek fd8136-vvtk-0300a
Vendors & Products Vivotek
Vivotek fd8136-vvtk-0300a

Tue, 02 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in VIVOTEK Camera Firmware Allows Remote Code Execution
Weaknesses CWE-119

Tue, 02 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component
References

Subscriptions

Vivotek Fd8136 Fd8136-vvtk-0300a Fd8136 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T13:42:09.797Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30649

cve-icon Vulnrichment

Updated: 2026-06-03T13:42:03.373Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-02T16:16:35.213

Modified: 2026-06-03T18:41:44.620

Link: CVE-2026-30649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T17:30:36Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow