CVE-2019-14457 describes a critical stack-based buffer overflow vulnerability affecting VIVOTEK IP Camera devices running firmware versions prior to 0x20x. This flaw, rated 9.8 CVSS (CRITICAL), allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service by sending a specially crafted HTTP header. While no public exploits (Metasploit, Nuclei, ExploitDB) are known and it's not on the KEV catalog, its high severity and network-based attack vector warrant immediate patching. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:vivotek:camera:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.