CVE-2020-11949: Vivotek CC8160(HS) Firmware

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices.

Affected products

  • Vivotek CC8160(HS) Firmware: up to and including 0113b
  • Vivotek CC8160 Firmware: up to and including 0113b
  • Vivotek CC8370-Hv Firmware: up to and including 0213b
  • Vivotek CC8371-Hv Firmware: up to and including 0113b
  • Vivotek CC9381-Hv Firmware: up to and including 0222g
  • Vivotek CD8371-Hntv Firmware: up to and including 0113b
  • Vivotek CD8371-HNVF2 Firmware: up to and including 0113b
  • Vivotek FD8166A-N Firmware: up to and including 0113b
  • Vivotek FD8166A Firmware: up to and including 0213b
  • Vivotek FD8167A Firmware: up to and including 0213b
  • Vivotek FD8169A Firmware: up to and including 0213b
  • Vivotek FD816B-HF2 Firmware: up to and including 0113b
  • Vivotek FD816B-Ht Firmware: up to and including 0113b
  • Vivotek FD816BA-HF2 Firmware: up to and including 0113b
  • Vivotek FD816BA-Ht Firmware: up to and including 0113b
  • Vivotek FD816C-HF2 Firmware: up to and including 0213b
  • Vivotek FD816CA-HF2 Firmware: up to and including 0113b
  • Vivotek FD8177-H Firmware: up to and including 0113b
  • Vivotek FD8177-Ht Firmware: up to and including 0113b
  • Vivotek FD8179-H Firmware: up to and including 0113b
  • Vivotek FD8182-f1 Firmware: up to and including 0113b
  • Vivotek FD8182-f2 Firmware: up to and including 0113b
  • Vivotek FD8182-T Firmware: up to and including 0113b
  • Vivotek FD8366-V Firmware: up to and including 0113b
  • Vivotek FD8367A-V Firmware: up to and including 0213b
  • and 169 more

Published 2020-05-28. Last modified 2026-06-17.