Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security.  The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
History

Wed, 14 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Vivotek ip7137 Firmware
CPEs cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*
cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*
Vendors & Products Vivotek ip7137 Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Vivotek
Vivotek ip7137
Vendors & Products Vivotek
Vivotek ip7137

Fri, 09 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security.  The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.
Title Unprotected RTSP stream in Vivotek IP7137 cameras
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2026-01-09T11:53:41.060Z

Updated: 2026-01-09T16:22:19.535Z

Reserved: 2025-11-21T10:41:30.019Z

Link: CVE-2025-66049

cve-icon Vulnrichment

Updated: 2026-01-09T16:22:12.106Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-09T12:15:53.420

Modified: 2026-01-14T17:48:18.313

Link: CVE-2025-66049

cve-icon Redhat

No data.