Back to search
CVE-2025-66050
Published: Jan 9, 2026
Modified: Jan 9, 2026
PUBLISHED
Description
Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
| Vendor | Product | Versions |
|---|---|---|
Vivotek | IP7137 | affected 0200a |
Weaknesses (CWE)
References
https://cert.pl/posts/2026/01/CVE-2025-66049
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now