peter bassill · operator
$ cve CVE-2018-14495 JSON

CVE-2018-14495

9.8
CRITICAL · CVSS 3.0 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.41% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-07-10
Last modified2026-06-17

Affected (2)

VendorProduct
vivotekfd8136
vivotekfd8136 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD