SQL Injection Vulnerability in 648540858 wvp-GB28181-pro Product
CVE-2026-4597
Key Information:
- Vendor
648540858
- Status
- Vendor
- CVE Published:
- 23 March 2026
Badges
What is CVE-2026-4597?
A security flaw has been identified in the Stream Proxy Query Handler of the wvp-GB28181-pro product, specifically involving the selectAll function in StreamProxyProvider.java. This vulnerability enables SQL injection attacks, which can be executed remotely, providing attackers the ability to manipulate database queries. The flaw affects all versions of the product up to 2.7.4. No response has been received from the vendor regarding this serious issue, raising concerns about the potential exploitation and the safety of users relying on the affected software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wvp-GB28181-pro 2.7.0
wvp-GB28181-pro 2.7.1
wvp-GB28181-pro 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
