Junglewise Threat Intelligence

CVE-2026-30650: Vivotek FD8136 buffer overflow in eventtask.cgi

CVE-2026-30650 · Severity: info · CVSS 8.8 · Published 2026-06-02

Technologies: VIVOTEK FD8136. Vendors: VIVOTEK.

Executive brief

A security vulnerability exists in Vivotek FD8136 network cameras, which are used for professional video surveillance. An attacker with valid login credentials can exploit this flaw to take full control of the camera. This could allow them to disable security monitoring, access private video feeds, or use the device as a foothold to attack other parts of the corporate network.

Technical details

A stack-based buffer overflow exists in the /cgi-bin/admin/eventtask.cgi endpoint of Vivotek FD8136 cameras running firmware FD8136-VVTK-0300a. The vulnerability occurs because the binary reads the raw POST request body from stdin into a fixed-size stack buffer (approximately 0x88 bytes) without performing bounds checking. An authenticated attacker can exploit this by sending a specially crafted POST request with a body exceeding the buffer size, allowing them to overwrite the saved link register and redirect control flow. The device lacks modern memory protections such as stack canaries, facilitating straightforward remote code execution with root privileges.

Affected products

  • Vivotek FD8136 FD8136-VVTK-0300a

Timeline

  • 2026-05: disclosed: Discovered by Lewis Patten
  • 2026-06-02: advisory: CVE published to NVD

References

Related threats