CVE-2025-66052General(vivotek / ip7137)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ip7137
  • ip7137_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ip7137ip7137_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-14: 1Technical Details · 2026-03-14: 103-14
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • ookin@neko@kal25252
    General

    🚨未知の脆弱性を狙った可能性のある攻撃を観測 攻撃パケットは投稿画像のとおりです。 該当するCVEは特定できませんでしたが、類似事例として CVE-2025-66052 が挙げられます。 このCVEは、Vivotek社製Webカメラ IP7137 に関するもので、/cgi-bin/admin/setparam.cgi エンドポイントで使用される system_ntpIt パラメータにペイロードを仕込むことで、任意のコマンドが実行可能となる脆弱性です。 今回観測したパケットでは、エンドポイントは同一である一方、使用されているパラメータは異なっており、ダイナミックDNSに関係すると思われるパラメータを使用していました。 攻撃が成功した場合、187.77.144.216 からファイルをダウンロードする挙動が想定されます。 ファイル名から判断すると、おそらく MIPS系CPU向けの実行ファイル である可能性がありますが、実際にはダウンロードできませんでした。 未知の脆弱性を悪用しようとした攻撃である可能性 も考えられます、注意ください。

    Post summary

    Traffic suggesting an attempt against a Vivotek IP camera’s /cgi-bin/admin/setparam.cgi endpoint—similar to CVE-2025-66052—was observed, but no definitive proof of exploitation or patch information was provided.

    00000268
    69 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWvivotekip7137---
OSvivotekip7137_firmware0200a--

Explore more