CRITICAL🇵🇱 Wersja polska

CVE-2026-7161

CVSS 9.3v3.1pub. 2026-05-04upd. 2026-06-15

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.

🤖 AI Analysis
How it works

The GV-IP Device Utility tool, when communicating with GeoVision devices on the network, sends privileged commands in the form of UDP broadcast packets containing encrypted user credentials. The encryption is based on a scheme derived from the Blowfish algorithm, however the symmetric key used for encryption is attached directly to the same packet. This means that the security of credentials relies solely on the secrecy of the encryption scheme (security through obscurity) rather than on key secrecy. A person eavesdropping on network traffic in the LAN segment — for example using a standard sniffer — can collect broadcast packets at the moment when an administrator uses the tool, and then independently implement the decryption algorithm and recover the login and password.

Impact

An attacker who recovers administrator credentials gains full control over the GeoVision device configuration — can change its IP address, restore factory settings, or perform other administrative operations.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://www.geovision.com.tw/cyber_security.php). Until updated, it is recommended to restrict access to the network segment where the tool operates and avoid using GV-IP Device Utility in untrusted network environments.

Who is affected

GeoVision GV-IP Device Utility version 9.0.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H
  • Geovision Gv Ip Device Utility

    APP
    Geovision
    9.0.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-11120CRITICAL9.8⚠ KEVPL ✓same vendor

OS Command Injection w urządzeniach GeoVision — zdalne wykonanie poleceń bez uwierzytelnienia

CVE-2024-6047CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w urządzeniach GeoVision EOL — zdalne wykonanie poleceń

CVE-2026-42364CRITICAL9.9PL ✓same vendor

Command injection w GeoVision LPC2011/LPC2211 via konfiguracja DDNS

CVE-2026-42368CRITICAL9.9PL ✓same vendor

Privilege escalation w interfejsie Web GeoVision LPC2011/LPC2211

CVE-2026-42370CRITICAL9.0PL ✓same vendor

Stack overflow w GeoVision GV-VMS — nieuwierzytelnione RCE przez WebCam Server