Stack Overflow Vulnerability in GV-I/O Box 4E by GeoVision
CVE-2026-12846
10CRITICAL
What is CVE-2026-12846?
The GV-I/O Box 4E by GeoVision contains a vulnerability that allows attackers to exploit a stack overflow through its DVRSearch service. This service, which operates by default and listens for UDP messages on port 10001, can be targeted by any user on the network. When it receives a UDP message, the server is susceptible to a stack overflow due to inadequate buffer handling within the code that processes the network mask. Specifically, the vulnerability arises when the net mask is copied to a local buffer without proper bounds checking, enabling potential attackers to manipulate the execution flow and compromise the device.
Affected Version(s)
GV-I/O Box 4E Linux V2.09
GV-I/O Box 4E Linux v2.12
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
