VYPR
Vendor

Geovision

Products
60
CVEs
80
Across products
117
Status
Private

Products

60
View all 60 products →

Recent CVEs

80
View all 80 CVEs →
  • CVE-2024-11120CriKEVNov 15, 2024
    risk 0.78cvss 9.8epss 0.29

    Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we…

  • CVE-2024-6047CriKEVJun 17, 2024
    risk 0.76cvss 9.8epss 0.10

    Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

  • CVE-2026-12848CriJun 24, 2026
    risk 0.65cvss 10.0epss 0.00

    GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service…

  • CVE-2026-12847CriJun 24, 2026
    risk 0.65cvss 10.0epss 0.00

    GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service…

  • CVE-2026-12846CriJun 24, 2026
    risk 0.65cvss 10.0epss 0.00

    GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service…

  • CVE-2026-12485CriJun 24, 2026
    risk 0.65cvss 10.0epss 0.01

    GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service…

  • CVE-2026-42369CriMay 4, 2026
    risk 0.65cvss 10.0epss 0.01

    GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is…

  • CVE-2026-4606CriMar 23, 2026
    risk 0.65cvss epss 0.00

    GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.  During installation, ERM creates a Windows service that runs under the LocalSystem account.  …

  • CVE-2018-25118CriOct 20, 2025
    risk 0.65cvss epss 0.01

    GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the…

  • CVE-2026-42368CriMay 4, 2026
    risk 0.64cvss 9.9epss 0.00

    A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.

  • CVE-2026-42364CriMay 4, 2026
    risk 0.64cvss 9.9epss 0.02

    An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

  • CVE-2023-3638CriJul 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

  • CVE-2023-23059CriMay 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.

  • CVE-2020-3931CriJul 8, 2020
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.

  • CVE-2019-11064CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1…

  • CVE-2025-26264HigFeb 27, 2025
    risk 0.62cvss 8.8epss 0.23

    GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary…

  • CVE-2026-7161CriMay 4, 2026
    risk 0.60cvss 9.3epss 0.00

    An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When…

  • CVE-2026-42363CriApr 27, 2026
    risk 0.60cvss 9.3epss 0.00

    An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When…

  • CVE-2024-56901HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.02

    A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a…

  • CVE-2024-56898HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.03

    Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.