Tag

#GeoVision

newsCRITICAL 9.1

Critical Vulnerability in GeoVision GV-AS1620 (GV-Cloud) Firmware

A critical vulnerability (CVE-2026-18754) with a CVSS score of 9.1 has been discovered in GeoVision GV-AS1620 (GV-Cloud) firmware, allowing malicious actors to breach the confidentiality and integrity of HTTPS communications. The vulnerability affects version V1.16 of the product. Immediate action is required to mitigate this vulnerability.

1 source
articleCRITICAL 9.1

Critical Vulnerability in GeoVision GV-AS1620: Embedded RSA Private Key Exposure

A critical vulnerability (CVE-2026-18753) with a CVSS score of 9.1 has been discovered in GeoVision's GV-AS1620 (AS-Manager) product. The vulnerability involves an embedded, static RSA private key used for TLS termination by the Lighttpd web server. Exposure of this private key could allow malicious actors to breach the confidentiality and integrity of HTTPS communications. The affected version is V2.07, and a patched version (V2.08) is available. Immediate patching is highly recommended.

1 source
newsCRITICAL 10.0

Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12846)

A critical stack overflow vulnerability (CVE-2026-12846) with a CVSS score of 10 has been discovered in GeoVision GV-I/O Box 4E, a smart embedded device. The vulnerability affects version V2.09 and can be exploited by sending a crafted UDP message to the DVRSearch service listening on port 10001. Immediate action is required to update to a non-vulnerable version.

1 source
articleCRITICAL 10.0

Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12485)

A critical stack overflow vulnerability (CVE-2026-12485) with a CVSS score of 10 has been discovered in GeoVision's GV-I/O Box 4E, a smart embedded device used for input and output control over Ethernet and RS-485. The vulnerability exists in the DVRSearch service, which listens for UDP messages on port 10001, allowing any network user to interact with it. Successful exploitation could lead to remote code execution, high impact on confidentiality, integrity, and availability. Affected versions include V2.09, and the vendor has released a patched version v2.12.

1 source