一个 API 密钥被硬编码并可以从应用程序包中提取。由于 Android 应用程序容易被逆向工程,将敏感的 API 凭据直接嵌入到客户端应用中,可能会导致未授权用户提取并滥用该密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-Eye | V3.6.0 |
affected |
V3.7.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-Eye | V3.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103096 | 7.5 HIGH | GV-Eye Hardcoded API Key Vulnerability |
| CVE-2026-103098 | 7.5 HIGH | GV-Eye Sensitive information exposure in URL query parameter Vulnerability |
No comments yet