CVE-2018-14494: Vivotek FD8136 Firmware

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware

Affected products

  • Vivotek FD8136 Firmware: version 0301a only

Published 2019-07-10. Last modified 2026-06-17.