Tag
#GeoVision
Critical Vulnerability in GeoVision GV-AS1620 (GV-Cloud) Firmware
A critical vulnerability (CVE-2026-18754) with a CVSS score of 9.1 has been discovered in GeoVision GV-AS1620 (GV-Cloud) firmware, allowing malicious actors to breach the confidentiality and integrity of HTTPS communications. The vulnerability affects version V1.16 of the product. Immediate action is required to mitigate this vulnerability.
Critical Vulnerability in GeoVision GV-AS1620: Embedded RSA Private Key Exposure
A critical vulnerability (CVE-2026-18753) with a CVSS score of 9.1 has been discovered in GeoVision's GV-AS1620 (AS-Manager) product. The vulnerability involves an embedded, static RSA private key used for TLS termination by the Lighttpd web server. Exposure of this private key could allow malicious actors to breach the confidentiality and integrity of HTTPS communications. The affected version is V2.07, and a patched version (V2.08) is available. Immediate patching is highly recommended.
Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12846)
A critical stack overflow vulnerability (CVE-2026-12846) with a CVSS score of 10 has been discovered in GeoVision GV-I/O Box 4E, a smart embedded device. The vulnerability affects version V2.09 and can be exploited by sending a crafted UDP message to the DVRSearch service listening on port 10001. Immediate action is required to update to a non-vulnerable version.
Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12485)
A critical stack overflow vulnerability (CVE-2026-12485) with a CVSS score of 10 has been discovered in GeoVision's GV-I/O Box 4E, a smart embedded device used for input and output control over Ethernet and RS-485. The vulnerability exists in the DVRSearch service, which listens for UDP messages on port 10001, allowing any network user to interact with it. Successful exploitation could lead to remote code execution, high impact on confidentiality, integrity, and availability. Affected versions include V2.09, and the vendor has released a patched version v2.12.