← Vulnerability feed

Vulnerability record · CVE-2018-14496 · published 10 July 2019

CVE-2018-14496: Vivotek fd8136 firmware out-of-bounds write vulnerability

Vivotek · Fd8136 Firmware

Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

9.8 CVSS 3.0 Critical EPSS 4.1% · top 9.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 7.5
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-14496 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14495Vivotek fd8136 firmware os command injection vulnerabilityVivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE…EPSS 4.4%9.8CVE-2018-14494Vivotek fd8136 firmware os command injection vulnerabilityVivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining th…EPSS 3.2%8.8CVE-2026-30650Vivotek fd8136 firmware classic buffer overflow vulnerabilityA post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD81…EPSS 0.89%8.8CVE-2026-30652Vivotek fd8136 firmware classic buffer overflow vulnerabilityA remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmwa…EPSS 0.76%7.3CVE-2026-30649Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityBuffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi componentEPSS 0.49%6.5CVE-2026-35718Vivotek fd8136 firmware path traversal vulnerabilityA path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to …EPSS 0.99%6.3CVE-2026-35716Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to …EPSS 0.44%6.3CVE-2026-35717Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2018-14496), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.