Remote Code Execution Vulnerability in GeoVision GV-ASWeb by GeoVision
CVE-2026-7841
8.8HIGH
What is CVE-2026-7841?
A remote code execution vulnerability exists in the Notification Settings of GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can exploit this flaw to execute arbitrary commands on the server. This is achieved by sending a specially crafted HTTP POST request to the ASWebCommon.srf backend endpoint, effectively bypassing frontend restrictions and compromising server integrity.
Affected Version(s)
ASManager Windows V6.2.0
ASManager Windows V6.3.0
