CVE-2025-26264
moderateAuthenticated RCE in GeoVision GV-ASWeb ≤ 6.1.2.0
GeoVision GV-ASWeb, the web management interface for GeoVision access control systems, contains a remote code execution flaw (CWE-94, code injection) in its Notification Settings feature. An authenticated attacker holding 'System Settings' privileges can submit crafted input through that feature to execute arbitrary commands on the host server over the network. Successful exploitation yields full compromise of the server, including confidentiality, integrity, and availability (CVSS 3.1 score 8.8, High). All organizations running GV-ASWeb version 6.1.2.0 or earlier are affected; version 6.2.0 contains the fix. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the high EPSS score (23% probability of exploitation within 30 days, 98th percentile) suggests defenders should prioritize patching.
What to do: Upgrade GV-ASWeb to version 6.2.0 or later. Until patched, restrict access to the ASWeb interface to trusted networks/VPNs, limit accounts holding 'System Settings' privileges to trusted administrators, and review Notification Settings for tampering; given the elevated EPSS score, treat patching as high priority.
| GeoVision GV-ASWeb | ≤ 6.1.2.0 (fixed in 6.2.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.