GeoVision Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with GV-VMS V20.0.2.
Products
Clear product- GeoWebPlayer18 vulnerabilities
- GV-LPCLPC2011/221110 vulnerabilities
- GV-I/O Box 4E8 vulnerabilities
- GV-LPC2011/LPC22116 vulnerabilities
- GV-IP Device Utility3 vulnerabilities
- GV-VMS V20.0.23 vulnerabilities
- ASManager1 vulnerability
- GeoVision1 vulnerability
- GeoVision embedded IP devices1 vulnerability
- GV-AS1620 (AS-Manager)1 vulnerability
- GV-AS1620 (GV-Cloud)1 vulnerability
- GV-ASManager1 vulnerability
- GV-BX15001 vulnerability
- GV-MFD15011 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42370CRITICAL | GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerabilityA stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. CWE-787May 4, 2026 | CVSS9.0v3.1 | EPSS0.547% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7372CRITICAL | GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerabilityA stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The call to `sscanf` at [1] to split the `Buffer` variable into the `username` and `password` variables doesn't limit the size of the extracted content to match the destination buffers… CWE-787May 4, 2026 | CVSS9.0v3.1 | EPSS0.475% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42369CRITICAL | GeoVision GV-VMS V20 WebCam Server stack overflow vulnerabilityGV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and monitoring feature via a regular Web interface. This webersever is another native application, compiled without ASLR, which makes exploitation much easier and more likely. Most … CWE-787May 4, 2026 | CVSS10.0v3.1 | EPSS0.537% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |