CVE-2018-25118

CRITICAL EXPLOITED

GeoVision embedded IP devices - Command Injection

Title source: llm

Description

GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

Exploits (1)

exploitdb WORKING POC
by bashis · textremotehardware
https://www.exploit-db.com/exploits/43982

Scores

CVSS v4 10.0
EPSS 0.0058
EPSS Percentile 69.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Details

VulnCheck KEV 2025-10-20
CWE
CWE-78
Status published
Products (3)
GeoVision Inc./GeoVision embedded IP devices < November/December 2017 firmware
GeoVision Inc./GV-BX1500 < November/December 2017 firmware
GeoVision Inc./GV-MFD1501 < November/December 2017 firmware
Published Oct 20, 2025
Tracked Since Feb 18, 2026