OS Command Injection Vulnerability in GeoVision GV-I/O Box by GeoVision
CVE-2026-12850
9.1CRITICAL
What is CVE-2026-12850?
The GeoVision GV-I/O Box version 4E 2.09 is susceptible to multiple OS command injection vulnerabilities through the libNetSetObj.so library. By sending specially crafted network packets, an attacker could execute arbitrary commands on the device. The issue arises from a lack of input sanitization in the gateway address handling, allowing exploitation via network-exposed services such as DVRSearch and the Network.cgi endpoint. This flaw enables attackers to manipulate critical network configurations, which poses significant risks to system integrity and security.
Affected Version(s)
GV-I/O Box 4E Linux V2.09
GV-I/O Box 4E Linux V2.12
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
