Executive Summary

A critical vulnerability (CVE-2026-18754) with a CVSS score of 9.1 has been discovered in GeoVision GV-AS1620 (GV-Cloud) firmware. This vulnerability allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. The affected product version is V1.16.

Technical Analysis

The vulnerability is caused by an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination in the product firmware. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. The vulnerability class is CWE-321, which refers to the use of hard-coded cryptographic keys.

How It Gets Exploited

An attacker with network access to the vulnerable device can exploit this vulnerability by accessing the embedded RSA private key. This can be done by sending a request to the Lighttpd web server, which uses the private key for TLS termination. Once the private key is exposed, an attacker can decrypt HTTPS traffic and spoof the server, allowing them to breach the confidentiality and integrity of HTTPS communications.

Impact Assessment

The affected product is GeoVision GV-AS1620 (GV-Cloud) with firmware version V1.16. The vulnerability has a CVSS score of 9.1, indicating a critical severity level. An attacker can achieve a high impact on confidentiality and integrity, with no impact on availability. The blast radius is high, as an attacker can exploit this vulnerability to breach the security of HTTPS communications.

Recommended Actions

To mitigate this vulnerability, it is recommended to update the GeoVision GV-AS1620 (GV-Cloud) firmware to version V1.17 or later. Additionally, users should ensure that the device is not accessible from the internet and limit access to the device to only trusted networks and users. It is also recommended to monitor the device for any suspicious activity and implement additional security measures, such as encryption and secure authentication.

Sources

  • National Vulnerability Database (NVD)
  • GeoVision Inc.