Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vivotek

First CVE: Jun 11, 2007Active for: 19 yearsTotal CVEs: 41
57.6
VTI Score
TOP TARGET

Vivotek manufactures a broad portfolio of network surveillance cameras and related firmware deployed across institutional and commercial security installations, presenting an attack surface concentrated in internet-facing imaging devices. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the appeal of camera systems for reconnaissance, lateral-movement staging, and botnet recruitment. The exposure recurs across product lines such as the FD and PT series cameras and their associated firmware through classic memory-safety and access-control weakness classes, including OS command injection, stack-based and classic buffer overflows, and path-traversal conditions that are typical of embedded imaging firmware with limited code-review discipline. Defenders should inventory Vivotek cameras in their environments, prioritize those exposed to untrusted networks, and apply security updates aggressively, since these devices frequently sit outside the managed-IT refresh cycle. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vivotek over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2007
19 years ago
Most Recent CVE
Jun 2, 2026
52 days ago

Products(436 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9828CRITICAL
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any she
Jun 23, 20179.876NONO
CVE-2017-9829HIGH
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux fi
Jun 23, 20177.561NONO
CVE-2013-1595CRITICAL
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which
Jan 24, 20209.857NOYES
CVE-2013-1598HIGH
A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user e
Jan 24, 20208.842NOYES
CVE-2008-4771HIGH
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecode
Oct 28, 20089.336NOYES
CVE-2026-30652HIGH
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. T
Jun 2, 20268.835NONO
CVE-2026-30650HIGH
A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware ver
Jun 2, 20268.834NONO
CVE-2024-7441CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the compon
Aug 3, 20249.832NONO
CVE-2013-1597MEDIUM
A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credential
Jan 24, 20206.532NOYES
CVE-2013-4985HIGH
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
Dec 27, 20197.532NOYES
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
24%
41%
34%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (95.1%)
Unknown2 (4.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (95.1%)
High0 (0.0%)
Unknown2 (4.9%)
User Interaction
None36 (87.8%)
Unknown2 (4.9%)
Required3 (7.3%)
Privileges Required
Low13 (31.7%)
High1 (2.4%)
None25 (61.0%)
Unknown2 (4.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
19.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vivotek.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vivotek — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vivotek's Products

View all 3 CNAs →

Top CWEs