2025/06/26 - 3.9.5 Vulnerability Incident FAQ

2025/06/26 - 3.9.5 Vulnerability Incident FAQ

Q: What was the identified vulnerability?

A vulnerability was identified in Vivi box firmware version 3.9.5 that could allow other devices on the same local network to access device management functions on affected Vivi units.

 

Q: What version/s of Vivi are affected by this vulnerability?

The vulnerability specifically affects 200 Series Vivi devices running firmware version 3.9.5.

  • Firmware 3.9.6 patches this vulnerability and all earlier versions prior to 3.9.5 are not affected.

  • 100 Series Boxes, the Vivi Receiver App and Vivi Display App are not affected even if running 3.9.5.

  • The Vivi Client App is unaffected

 

Q: What steps should be taken on affected devices?

Customers should update affected 200 Series Vivi devices to firmware version 3.9.6, which includes a fix for the vulnerability. Alternatively, as versions 3.9.4 and earlier are not affected, downgrading is also an option.

 

Q: What is the risk if the patch is not applied?

If the patch is not applied, there is a risk that other devices on the same local network could potentially gain control of or disrupt the services of 200 Series Vivi devices.

 

Q: Do you have a CVE ID?

CVE (Common Vulnerabilities and Exposures):

At this stage, the vulnerability in version 3.9.5 hasn’t been assigned a CVE ID. CVEs are part of a public system for cataloging known security issues, often used by vulnerability scanners and compliance tools.
While this issue is real and serious, it hasn’t been submitted for CVE publication. That said, we’ve already identified the root cause, are actively deploying the fix (version 3.9.6), and there’s no evidence of exploitation in the field.
If a CVE is assigned later, we’ll update customers accordingly so it can be tracked through any standard vulnerability management platforms