Websocket Server Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-13132

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-13132?

GeoWebPlayer, often referred to as 'Web Plugin' in the GV-VMS documentation, acts as an addon for various GeoVision software. This component creates a websocket server that is essential for extending the functionalities of the web interfaces provided by the GeoVision software. However, this websocket server has a security flaw where the index values it accepts for executing commands are not adequately validated, allowing potential out-of-bounds access. Such access can lead to unauthorized manipulation of critical arrays and functions within the system, posing a significant risk to the integrity and stability of the affected software.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.