Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| http://www.vapidlabs.com/advisory.php?v=220 |
|
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek fd8365 Vivotek fd8365v2 Vivotek fd9165 Vivotek fd9171 Vivotek fd9187 Vivotek fd9189 Vivotek fd9365 Vivotek fd9371 Vivotek fd9381 Vivotek fd9387 Vivotek fd9389 Vivotek fd9391 Vivotek fe9180 Vivotek fe9181 Vivotek fe9191 Vivotek fe9381 Vivotek fe9382 Vivotek fe9391 Vivotek fe9582 Vivotek ib93587lpr Vivotek ib9365 Vivotek ib9371 Vivotek ib9381 Vivotek ib9387 Vivotek ib9389 Vivotek ib939 Vivotek ip9165 Vivotek ip9171 Vivotek ip9172 Vivotek ip9181 Vivotek ip9191 Vivotek it9389 Vivotek ma9321 Vivotek ma9322 Vivotek ms9321 Vivotek ms9390 Vivotek tb9330 |
|
| Vendors & Products |
Vivotek
Vivotek fd8365 Vivotek fd8365v2 Vivotek fd9165 Vivotek fd9171 Vivotek fd9187 Vivotek fd9189 Vivotek fd9365 Vivotek fd9371 Vivotek fd9381 Vivotek fd9387 Vivotek fd9389 Vivotek fd9391 Vivotek fe9180 Vivotek fe9181 Vivotek fe9191 Vivotek fe9381 Vivotek fe9382 Vivotek fe9391 Vivotek fe9582 Vivotek ib93587lpr Vivotek ib9365 Vivotek ib9371 Vivotek ib9381 Vivotek ib9387 Vivotek ib9389 Vivotek ib939 Vivotek ip9165 Vivotek ip9171 Vivotek ip9172 Vivotek ip9181 Vivotek ip9191 Vivotek it9389 Vivotek ma9321 Vivotek ma9322 Vivotek ms9321 Vivotek ms9390 Vivotek tb9330 |
Tue, 13 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use of default login credentials in Legacy Vivotek Devices | Remote code injection via upload_map.cgi in Legacy Vivotek Devices |
Tue, 13 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Vivotek Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330 (Firmware modules) allows OS Command Injection.This issue affects Affected device model numbers are FD8365, FD8365v2, FD9165, FD9171, FD9187, FD9189, FD9365, FD9371, FD9381, FD9387, FD9389, FD9391,FE9180,FE9181, FE9191, FE9381, FE9382, FE9391, FE9582, IB9365, IB93587LPR, IB9371,IB9381, IB9387, IB9389, IB939,IP9165,IP9171, IP9172, IP9181, IP9191, IT9389, MA9321, MA9322, MS9321, MS9390, TB9330: 0100a, 0106a, 0106b, 0107a, 0107b_1, 0109a, 0112a, 0113a, 0113d, 0117b, 0119e, 0120b, 0121, 0121d, 0121d_48573_1, 0122e, 0124d_48573_1, 012501, 012502, 0125c. | |
| Title | Use of default login credentials in Legacy Vivotek Devices | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: larry_cashdollar
Published: 2026-01-13T15:12:53.126Z
Updated: 2026-01-13T21:23:03.598Z
Reserved: 2026-01-09T14:27:11.646Z
Link: CVE-2026-22755
Updated: 2026-01-13T15:29:47.058Z
Status : Received
Published: 2026-01-13T15:16:01.193
Modified: 2026-01-13T22:16:07.833
Link: CVE-2026-22755
No data.