ZeroHour

CVE-2025-26264

moderate

Authenticated RCE in GeoVision GV-ASWeb ≤ 6.1.2.0

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
Modified
AI analysis

GeoVision GV-ASWeb, the web management interface for GeoVision access control systems, contains a remote code execution flaw (CWE-94, code injection) in its Notification Settings feature. An authenticated attacker holding 'System Settings' privileges can submit crafted input through that feature to execute arbitrary commands on the host server over the network. Successful exploitation yields full compromise of the server, including confidentiality, integrity, and availability (CVSS 3.1 score 8.8, High). All organizations running GV-ASWeb version 6.1.2.0 or earlier are affected; version 6.2.0 contains the fix. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the high EPSS score (23% probability of exploitation within 30 days, 98th percentile) suggests defenders should prioritize patching.

What to do: Upgrade GV-ASWeb to version 6.2.0 or later. Until patched, restrict access to the ASWeb interface to trusted networks/VPNs, limit accounts holding 'System Settings' privileges to trusted administrators, and review Notification Settings for tampering; given the elevated EPSS score, treat patching as high priority.

Affected
GeoVision GV-ASWeb≤ 6.1.2.0 (fixed in 6.2.0)
Estimated exposure
moderateroughly 10,000–100,000 deployments worldwide (estimated; no public per-product install counts) — No public install counts exist for GV-ASWeb specifically, so this extrapolates from GeoVision's sizable global installed base in physical security and the deployment pattern of one ASManager/ASWeb server per access-control site, with only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.