Vulnerability Description
A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vivotek | Fd8136 Firmware | 0300a |
| Vivotek | Fd8136 | - |
Related Weaknesses (CWE)
References
- https://github.com/xchg-rax-rax/vulnerability-research/tree/main/CVE-2026-35717Third Party Advisory
FAQ
What is CVE-2026-35717?
CVE-2026-35717 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST ...
How severe is CVE-2026-35717?
CVE-2026-35717 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35717?
Check the references section above for vendor advisories and patch information. Affected products include: Vivotek Fd8136 Firmware, Vivotek Fd8136.