Mehrere Schwachstellen (CVE-2026-12485, CVE-2026-12486, CVE-2026-12846, CVE-2026-12847, CVE-2026-12848, CVE-2026-12849, CVE-2026-12850, CVE-2026-12851) in Geovision
⚠️ CVE-Referenzen:
CVE-2026-12485
CVE-2026-12486
CVE-2026-12846
CVE-2026-12847
CVE-2026-12848
CVE-2026-12849
CVE-2026-12850
CVE-2026-12851
Geovision Inc. - Gv-i/o Box 4e - CRITICAL - CVE-2026-12851.
Multiple OS command injection vulnerabilities exist in the internal library libNetSetObj.so of the GeoVision GV-I/O Box 4E 2.09. These vulnerabilities allow an attacker to execute arbitrary commands by sending specially crafted network packets. The unauthorized command execution can be initiated through functions like m_F_n_Set_DNS_Addr, which performs no input sanitization and directly calls the system command with user-controlled input. This issue is accessible through network-exposed services such as DVRSearch and Network.cgi, highlighting a significant risk to the device's network configuration and overall security.
Quelle: securityvulnerability.io