CVE-2025-66049 is an information disclosure vulnerability affecting Vivotek IP7137 cameras, specifically firmware version 0200a and potentially all versions. The vulnerability allows unauthenticated access to live camera footage via the RTSP protocol on port 8554, compromising user privacy. With a CVSS score of 7.5 (High), this network-based attack requires no user interaction and results in high confidentiality impact. As the product is End-Of-Life, no patch is expected, and there is currently no public exploit code, active exploitation, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0200aCPE matchmatch criteria | cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.