Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek fd8136 Firmware
|
|
| CPEs | cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek fd8136 Firmware
|
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Buffer Overflow in VIVOTEK Camera Firmware Allows Root Code Execution |
Wed, 03 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Buffer Overflow in VIVOTEK FD8136 Motion Privacy CGI | |
| Weaknesses | CWE-119 CWE-787 |
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek fd8136 |
|
| Vendors & Products |
Vivotek
Vivotek fd8136 |
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Buffer Overflow in VIVOTEK FD8136 Motion Privacy CGI | |
| Weaknesses | CWE-119 CWE-121 CWE-787 |
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-03T13:38:31.550Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35716
Updated: 2026-06-03T13:38:21.682Z
Status : Analyzed
Published: 2026-06-02T16:16:37.187
Modified: 2026-06-03T18:40:11.570
Link: CVE-2026-35716
No data.
OpenCVE Enrichment
Updated: 2026-06-03T17:30:36Z