Arbitrary Code Execution Vulnerability in GeoVision GV-VMS WebCam Server
CVE-2026-42370

9CRITICAL

Key Information:

Vendor
CVE Published:
4 May 2026

What is CVE-2026-42370?

A critical vulnerability exists in the WebCam Server Login functionality of GeoVision's GV-VMS product. An attacker can exploit this stack overflow by sending a specially crafted HTTP request that may allow for arbitrary code execution. This vulnerability requires no authentication, enabling unauthorized entities to trigger it, posing serious security risks to affected systems.

Affected Version(s)

GV-VMS V20.0.2 Windows 20.0.2

GV-VMS V20.0.2 Windows 21.0.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
.