Arbitrary Code Execution Vulnerability in GeoVision GV-VMS WebCam Server
CVE-2026-42370
9CRITICAL
What is CVE-2026-42370?
A critical vulnerability exists in the WebCam Server Login functionality of GeoVision's GV-VMS product. An attacker can exploit this stack overflow by sending a specially crafted HTTP request that may allow for arbitrary code execution. This vulnerability requires no authentication, enabling unauthorized entities to trigger it, posing serious security risks to affected systems.
Affected Version(s)
GV-VMS V20.0.2 Windows 20.0.2
GV-VMS V20.0.2 Windows 21.0.0
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
