CVE-2026-35718

MEDIUM

VIVOTEK INC FD8136-VVTK 0300a - Authenticated Path Traversal via /admin/downloadMedias.cgi

Title source: llm
STIX 2.1

Description

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.

Scores

CVSS v3 6.5
EPSS 0.0074
EPSS Percentile 49.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
vivotek/fd8136_firmware 0300a
Published Jun 02, 2026
Tracked Since Jun 02, 2026