← Vulnerability feed

Vulnerability record · CVE-2026-30650 · published 2 June 2026

CVE-2026-30650: Vivotek fd8136 firmware classic buffer overflow vulnerability

Vivotek · Fd8136 Firmware

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.

8.8 CVSS 3.1 High EPSS 0.89% · top 42.3% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30650 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14495Vivotek fd8136 firmware os command injection vulnerabilityVivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE…EPSS 4.4%9.8CVE-2018-14496Vivotek fd8136 firmware out-of-bounds write vulnerabilityVivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_…EPSS 4.1%9.8CVE-2018-14494Vivotek fd8136 firmware os command injection vulnerabilityVivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining th…EPSS 3.2%8.8CVE-2026-30652Vivotek fd8136 firmware classic buffer overflow vulnerabilityA remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmwa…EPSS 0.76%7.3CVE-2026-30649Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityBuffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi componentEPSS 0.49%6.5CVE-2026-35718Vivotek fd8136 firmware path traversal vulnerabilityA path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to …EPSS 0.99%6.3CVE-2026-35716Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to …EPSS 0.44%6.3CVE-2026-35717Vivotek fd8136 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-30650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.