CVE-2018-14495
9.8
CRITICAL · CVSS 3.0 · EPSS 4.4% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.41% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-10 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| vivotek | fd8136 |
| vivotek | fd8136 firmware |
References
- https://www.vdalabs.com/2018/07/23/professional-iot-hacking-series-target-selection-firmware-analysis/
- https://www.vdalabs.com/2018/08/06/professional-iot-hacking-series-hunting-remote-command-injection/
- https://www.vdalabs.com/2018/07/23/professional-iot-hacking-series-target-selection-firmware-analysis/
- https://www.vdalabs.com/2018/08/06/professional-iot-hacking-series-hunting-remote-command-injection/
→ the Explorer · watch your stack · NVD