CVE-2025-66050 describes a critical authentication bypass vulnerability in the Vivotek IP7137 camera, specifically with firmware version 0200a, where it defaults to no administrator password. This allows unauthenticated attackers to gain full control of the device. With a CVSS score of 9.8, the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Although the product is End-Of-Life and no fix is expected, there is no public exploit code or evidence of active exploitation, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0200aCPE matchmatch criteria | cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.