← Back

Geovision

geovision

27 CVEs • 77 products

Products (77)

Click to collapse
Toggle
Geohttpserver
geohttpserver
Gv Asmanager
gv-asmanager
Gv Vr360
gv-vr360
Gv Vd8700
gv-vd8700
Gv Gf192x
gv-gf192x
Gv As210
gv-as210
Gv As410
gv-as410
Gv As810
gv-as810
Gv Gf1921
gv-gf1921
Gv As1010
gv-as1010
Gv Gf1922
gv-gf1922
Gv Adr2701
gv-adr2701
Gv Dsp Lpr
gv-dsp_lpr
Gv Bx130
gv-bx130
Gv Bx1500
gv-bx1500
Gv Cb220
gv-cb220
Gv Ebl1100
gv-ebl1100
Gv Efd1100
gv-efd1100
Gv Fd2410
gv-fd2410
Gv Fd3400
gv-fd3400
Gv Fe3401
gv-fe3401
Gv Fe420
gv-fe420
Gv Vs14
gv-vs14
Gv Vs03
gv-vs03
Gv Vs2410
gv-vs2410
Gv Vs21600
gv-vs21600
Gv Vs04a
gv-vs04a
Gv Vs04h
gv-vs04h
Gvlx 4
gvlx_4
Gv Vs2800
gv-vs2800
Gv Vs2820
gv-vs2820
Gv Vs12
gv-vs12
Gv Vs11
gv-vs11
Gv Lpc2011
gv-lpc2011
Gv Lpc2211
gv-lpc2211
Gv Vms
gv-vms

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Geovision
1Gv Vms Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthentic...Show more
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The call to `sscanf` at [1] to split the `Buffer` variable into the `username` and `password` variables doesn't limit the size of the extracted content to match the destination buffers' sizes. In this case, if either the username or password decoded from the authorization string exceeds `40` characters (the size the stack variables `username` and `password`) then a stack overflow will occur. The data is controlled by an attacker, but sronger constraints (e.g. no null bytes) may make exploitation harder. A successful attack could lead to full code execution as SYSTEM on the machine running the service.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript co...Show more
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.Show less
1Geovision
1Gv Ip Device Utility
Jun 17, 2026
May 4, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to b...Show more
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.Show less
1Geovision
1Gv Vms Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthentic...Show more
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpag...Show more
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage t...Show more
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript co...Show more
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can brute...Show more
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.Show less
1Geovision
2Gv Lpc2011 Firmware
Gv Lpc2211 Firmware
Jun 17, 2026
May 4, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify...Show more
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.Show less
1Geovision
1Gv Asmanager
Jun 17, 2026
Dec 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Althoug...Show more
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.Show less
1Geovision
4Gv Dsp Lpr Firmware
Gv Vs11 FirmwareGv Vs12 Firmware+1 more
Jun 17, 2026
Nov 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vuln...Show more
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.Show less
1Geovision
20Gv Bx130 Firmware
Gv Bx1500 FirmwareGv Cb220 Firmware+17 more
Jun 17, 2026
Jun 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the devi...Show more
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.Show less
1Geovision
1Gv Asmanager
Jun 17, 2026
Mar 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.
1Geovision
1Gv Adr2701 Firmware
Jun 17, 2026
Jul 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
1Geovision
1Gv Edge Recording Manager
Jul 9, 2026
May 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated pr...Show more
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.Show less
1Geovision
6Gv As1010 Firmware
Gv As210 FirmwareGv As410 Firmware+3 more
Jun 17, 2026
Jul 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.
1Geovision
1Gv Gf192x Firmware
Jun 17, 2026
Jun 12, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.
2Androvideo
Geovision
3Gv Vd8700 Firmware
Gv Vr360 FirmwareVd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
2Androvideo
Geovision
3Gv Vd8700 Firmware
Gv Vr360 FirmwareVd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not es...Show more
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.Show less
2Androvideo
Geovision
3Gv Vd8700 Firmware
Gv Vr360 FirmwareVd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password...Show more
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.Show less