Vulnerabilities
20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42370 +1 in the same advisory: …7372 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-42368 | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability. NVD description · AI analysis pending | 9.9 group max | <1% |
| — | ||
| CVE-2026-7161 | An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2024-12553 | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-11120 | Unauthenticated OS Command Injection in GeoVision Devices Multiple GeoVision devices contain an unauthenticated OS command injection flaw (CWE-78) that allows a remote attacker to inject and execute arbitrary system commands on the device. Because no authentication is required, any party that can reach an affected device's network services can trigger the flaw with crafted input; no public proof-of-concept is known. Successful exploitation gives the attacker remote command execution on the device, which can be used to compromise surveillance infrastructure or pivot into connected networks. Organizations running GeoVision devices are affected, and CISA notes the impacted products may be end-of-life (EoL) and/or end-of-service (EoS), meaning some may no longer receive fixes. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-07, confirming exploitation in the wild; EPSS estimates a 28.4% probability of exploitation in the next 30 days (98th percentile), and ransomware use is not yet confirmed. Do: Inventory all GeoVision devices (including EoL/EoS models) and consult the vendor advisory for affected models and any available firmware mitigations or patches. Restrict internet exposure of GeoVision devices while remediating (firewall rules/ACLs, remove direct port forwarding), and replace or retire EoL/EoS units if the vendor offers no mitigation. Because the flaw is confirmed exploited in the wild, check devices for signs of compromise and unusual outbound traffic. | 9.8 | 28% | KEV PoC |
| largeon the order of tens of thousands of internet-exposed GeoVision devices, with a larger legacy installed base | |
| CVE-2024-6047 | Unauthenticated OS Command Injection in End-of-Life GeoVision Devices CVE-2024-6047 is an unauthenticated OS command injection flaw (CWE-78) in certain end-of-life GeoVision surveillance devices, which fail to properly filter user input for a specific functionality. A remote attacker can trigger it by sending crafted input to the affected device over the network with no authentication required, causing arbitrary system commands to be injected and executed on the device. Successful exploitation grants attackers control of the device, which has been leveraged to recruit GeoVision units into Mirai botnets. Organizations still running the listed EOL GeoVision devices (e.g., GV-BX, GV-CB, GV-EBL, GV-EFD, GV-FD, GV-FE series devices, GV-DSP LPR units, and GV-VS14/GV-GM8186 VS14 units) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-07, Akamai has documented active Mirai-based exploitation, and EPSS puts the 30-day exploitation probability at about 10%. Do: Inventory internet-facing GeoVision devices, identify the listed EOL models, and apply mitigations per vendor instructions (e.g., restrict web/management access to trusted networks) or discontinue use and replace the devices if mitigations are unavailable, since the affected devices are end-of-life. US federal agencies must remediate per BOD 22-01 following the KEV listing. Given active Mirai botnet exploitation and ~10% EPSS, prioritize devices exposed to the internet and check for anomalous outbound traffic consistent with botnet activity. | 9.8 | 10% | KEV PoC |
| largeLikely tens of thousands of internet-exposed GeoVision devices (order of magnitude 10k–100k); exact count unknown | |
| CVE-2022-46070 | GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-3638 | In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-23059 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allo An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-3931 | Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command. Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-3930 | GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs. GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs. NVD description · AI analysis pending | 3.3 | <1% |
| — | ||
| CVE-2019-11064 | A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — |