CVE-2026-12485

CRITICAL

GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-12485. PoCs published by 0xBlackash.

AI-analyzed exploit summary The repository contains a Python script that safely checks for the presence of CVE-2026-12485 by sending benign UDP probes to the GeoVision GV-I/O Box 4E DVRSearch service. It does not exploit the vulnerability but detects if the service is active and performs safe length tests.

Description

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### IP field stack overflow The following code is vulnerable to a stack overflow that is attacker-controlled: v3 = strlen(g_network_config->ip_addr); memcpy(&reply_buf[36], g_network_config->ip_addr, v3);

Exploits (1)

github SCANNER
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2026-12485

The repository contains a Python script that safely checks for the presence of CVE-2026-12485 by sending benign UDP probes to the GeoVision GV-I/O Box 4E DVRSearch service. It does not exploit the vulnerability but detects if the service is active and performs safe length tests.

Classification
Scanner 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: GeoVision GV-I/O Box 4E Firmware v2.09
No auth needed
Prerequisites: Network access to the target device on UDP port 10001
mistral-large-3 · analyzed Jun 28, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.geovision.com.tw/cyber_security.php

Scores

CVSS v3 10.0
EPSS 0.0063
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-121
Status published
Products (2)
GeoVision Inc./GV-I/O Box 4E V2.09
GeoVision Inc./GV-I/O Box 4E v2.12
Published Jun 24, 2026
Tracked Since Jun 24, 2026