Home

Description

Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

PUBLISHED Reserved 2025-11-01 | Published 2025-11-19 | Updated 2025-11-19 | Assigner larry_cashdollar




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Red

Problem types

CWE-1392 CWE-1392: Use of Default Credentials

Product status

Default status
unaffected

0100b (custom)
affected

0100e
affected

0100e1
affected

0100e2
affected

0100f
affected

0100g
affected

0100i
affected

0101c
affected

0103c
affected

0199z
affected

0200a
affected

0200b
affected

0200c
affected

0200g
affected

0201a
affected

0201a1
affected

0201c
affected

0201k
affected

0202a
affected

0202b
affected

0203a
affected

0300a
affected

0300b
affected

0301b3
affected

0302a
affected

0302c
affected

0400a
affected

0400b
affected

0401a
affected

0500a
affected

0500b
affected

Credits

Larry W. Cashdollar finder

References

www.akamai.com/...ch/rce-zero-day-in-legacy-vivotek-firmware

www.vapidlabs.com/advisory.php?v=219

cve.org (CVE-2025-12592)

nvd.nist.gov (CVE-2025-12592)

Download JSON