Stack Overflow Vulnerability in GV-I/O Box 4E by GeoVision
CVE-2026-12848

10CRITICAL

Key Information:

Vendor
CVE Published:
24 June 2026

What is CVE-2026-12848?

The GV-I/O Box 4E, a smart embedded device from GeoVision, is susceptible to a stack overflow vulnerability due to improper handling of UDP messages. The device listens for messages on port 10001, allowing any user on the network to interact with the DVRSearch service. When receiving a UDP message, the server attempts to read data into a local buffer based on the DNS address length, potentially overflowing the buffer if the input exceeds the buffer's capacity. This flaw can lead to arbitrary code execution and other malicious exploits if exploited by attackers.

Affected Version(s)

GV-I/O Box 4E Linux V2.09

GV-I/O Box 4E Linux v2.12

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.