CVE-2026-35718
MEDIUMVIVOTEK INC FD8136-VVTK 0300a - Authenticated Path Traversal via /admin/downloadMedias.cgi
Title source: llmDescription
A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.
References (2)
Core 2
Scores
CVSS v3
6.5
EPSS
0.0074
EPSS Percentile
49.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
vivotek/fd8136_firmware
0300a
Published
Jun 02, 2026
Tracked Since
Jun 02, 2026