Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek fd8136
|
|
| CPEs | cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek fd8136
|
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Code Execution via Stack Overflow in VIVOTEK FD8136 Export Language CGI |
Wed, 03 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Code Execution via Buffer Overflow in export_language.cgi | |
| Weaknesses | CWE-119 |
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
cvssV3_1
|
Tue, 02 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Remote Code Execution via Buffer Overflow in export_language.cgi | |
| First Time appeared |
Vivotek
Vivotek fd8136 Firmware |
|
| Weaknesses | CWE-119 | |
| Vendors & Products |
Vivotek
Vivotek fd8136 Firmware |
Tue, 02 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-03T13:43:23.776Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35717
Updated: 2026-06-03T13:43:18.147Z
Status : Analyzed
Published: 2026-06-02T14:16:51.123
Modified: 2026-06-03T18:42:05.617
Link: CVE-2026-35717
No data.
OpenCVE Enrichment
Updated: 2026-06-03T17:30:36Z