CVE-2025-66052 - CVE House
Back to Database
Status published High CVE-2025-66052

Command injection in Vivotek IP7137 cameras

Vulnerability Description

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66052

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Szymon Paszun

Affected Vendor

Affected Software

IP7137
Vulnerable Versions:
0200a

Timeline

Official Publish: January 9th, 2026
Last Modified: January 9th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)