Back to Database
Status published
Critical
CVE-2025-12592
Use of default login credentials in Legacy Vivotek Devices
Vulnerability Description
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12592
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Larry W. Cashdollar
References
More from Vivotek
View All →CVE-2025-66052
Command injection in Vivotek IP7137 cameras
High
8.6
CVE-2025-66051
Path traversal in Vivotek IP7137 cameras
Medium
6.9
CVE-2025-66050
No password set for administrative account in Vivotek IP7137 cameras
Critical
9.3
CVE-2025-66049
Unprotected RTSP stream in Vivotek IP7137 cameras
High
8.7
CVE-2025-3403
Vivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in source
Medium
5.1
Affected Vendor
Vivotek
View all reports →Affected Software
Affected device model numbers are FD7131-VVTK,FD7131-VVTK,FD7131-VVTK,FD7141-VVTK,IP7131-VVTK,IP7133-VVTK,IP7133-VVTK,IP7133-VVTK,IP7134-VVTK,IP7135-VVTK,IP7135-VVTK,IP7135-VVTK,IP7135-VVTK,IP7137-VVTK,IP7137-VVTK,IP7137-VVTK,IP7137-VVTK,IP7137-VVTK,IP7137-VVTK,IP7138-VVTK,IP7142-VVTK,IP7142-VVTK,IP7151-VVTK,IP7152-VVTK,IP7153-VVTK,IP7153-VVTK,IP7154-VVTK,IP7330-VVTK,IP7330-VVTK,IP7330-VVTK,IP8131-VVTK,IP8131-VVTK,IP8131-VVTK,IP8131W-VVTK,PT7135-VVTK,PT7137-TCON,PT7137-VVTK,PT7137-VVTK,PT7137-VVTK,PT7137-VVTK,PZ7131-VVTK,PZ7131-VVTK,PZ71X1-VVTK,PZ71X1-VVTK,PZ71X2-VVTK,SD73X3-VVTK,SD73X3-VVTK,SD73X3-VVTK,TC5330-VVTK,TC5332-TCVV,TC5333-TCVV,TC5633-TCVV,TC5633-VVTK,VS7100-VVTK,VS7100-VVTK,VS7100-VVTK
Vulnerable Versions:
0100b, 0100e, 0100e1, 0100e2, 0100f, 0100g, 0100i, 0101c, 0103c, 0199z, 0200a, 0200b, 0200c, 0200g, 0201a, 0201a1, 0201c, 0201k, 0202a, 0202b, 0203a, 0300a, 0300b, 0301b3, 0302a, 0302c, 0400a, 0400b, 0401a, 0500a, 0500b
Timeline
Official Publish:
November 19th, 2025
Last Modified:
November 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.