GeoVision Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with GV-BX1500.
Products
Clear product- GeoWebPlayer18 vulnerabilities
- GV-LPCLPC2011/221110 vulnerabilities
- GV-I/O Box 4E8 vulnerabilities
- GV-LPC2011/LPC22116 vulnerabilities
- GV-IP Device Utility3 vulnerabilities
- GV-VMS V20.0.23 vulnerabilities
- ASManager1 vulnerability
- GeoVision1 vulnerability
- GeoVision embedded IP devices1 vulnerability
- GV-AS1620 (AS-Manager)1 vulnerability
- GV-AS1620 (GV-Cloud)1 vulnerability
- GV-ASManager1 vulnerability
- GV-BX15001 vulnerability
- GV-MFD15011 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25118CRITICAL | GeoVision Command Injection RCE via /PictureCatch.cgiGeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. CWE-78Oct 20, 2025 | CVSS10.0v4.0 | EPSS1.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |