CRITICAL🇵🇱 Wersja polska

CVE-2026-42370

CVSS 9.0v3.1pub. 2026-05-04upd. 2026-06-15

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability results from a stack overflow error (CWE-787) in the WebCam Server login handler module. The attacker sends a specially crafted HTTP request to the vulnerable endpoint, which causes a buffer overflow on the stack. This results in overwriting data that controls program execution, allowing the attacker to execute arbitrary code in the context of the server process. Exploitation requires no prior authentication or user interaction.

Impact

An attacker can gain the ability to execute arbitrary code on the device (RCE), which can lead to complete takeover of the video management system, loss of recording confidentiality, violation of system integrity, and its unavailability.

Mitigation & patch

Apply patches available from the manufacturer according to the references. The manufacturer provides information about security updates at https://www.geovision.com.tw/cyber_security.php. Until patches are applied, it is recommended to restrict network access to the WebCam Server interface only to trusted IP addresses and to isolate GV-VMS devices in a separate network segment (VLAN) behind a firewall.

Who is affected

GeoVision GV-VMS V20, version 20.0.2 (GeoVision GV-VMS Firmware and GeoVision GV-VMS application)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Geovision Gv Vms

    HW
    Geovision
    20
  • Geovision Gv Vms Firmware

    OS
    Geovision
    < 21.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-7372CRITICAL9.0PL ✓same product

Stack overflow w GeoVision GV-VMS — niezautoryzowane RCE przez WebCam Server

CVE-2024-11120CRITICAL9.8⚠ KEVPL ✓same vendor

OS Command Injection w urządzeniach GeoVision — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2024-6047CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w urządzeniach GeoVision EOL — zdalne wykonanie poleceń

CVE-2026-42364CRITICAL9.9PL ✓same vendor

Command injection w GeoVision LPC2011/LPC2211 via konfiguracja DDNS

CVE-2026-42368CRITICAL9.9PL ✓same vendor

Privilege escalation w interfejsie Web GeoVision LPC2011/LPC2211