在未经加密的 HTTP 连接中通过 URL 传输敏感密钥。由于请求是通过 HTTP(而非 HTTPS)发送的,该密钥将以明文形式在网络中传输。能够监控网络流量的攻击者可以拦截该请求并获取该密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-Eye | V3.6.0 |
affected |
V3.7.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-Eye | V3.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103097 | 7.5 HIGH | GV-Eye Relay Payment API Key Vulnerability |
| CVE-2026-103096 | 7.5 HIGH | GV-Eye Hardcoded API Key Vulnerability |
No comments yet