Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Path Traversal Allowing Full File Read in VIVOTEK Device | |
| Weaknesses | CWE-20 |
Wed, 03 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek fd8136
Vivotek fd8136 Firmware |
|
| CPEs | cpe:2.3:h:vivotek:fd8136:-:*:*:*:*:*:*:* cpe:2.3:o:vivotek:fd8136_firmware:0300a:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vivotek fd8136
Vivotek fd8136 Firmware |
Wed, 03 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vivotek
Vivotek fd8136-vvtk Firmware |
|
| Vendors & Products |
Vivotek
Vivotek fd8136-vvtk Firmware |
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Path Traversal Allowing Full File Read in VIVOTEK Device | |
| Weaknesses | CWE-20 CWE-22 |
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-03T17:35:11.892Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35718
Updated: 2026-06-03T17:34:20.752Z
Status : Modified
Published: 2026-06-02T16:16:37.330
Modified: 2026-06-03T19:16:26.013
Link: CVE-2026-35718
No data.
OpenCVE Enrichment
Updated: 2026-06-03T21:30:32Z