GeoVision GV-ASManager是中国GeoVision公司的一套网络访问控制解决方案。 GeoVision GV-ASManager V6.3.0版本存在权限许可和访问控制问题漏洞,该漏洞源于DLL搜索路径不安全,可能导致本地攻击者利用不安全搜索目录的写权限放置精心构造的动态链接库文件,在合法库之前加载并以GV-ASManager进程权限执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-ASManager | V6.3.0 |
affected |
V6.4.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-ASManager | V6.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18754 | 9.1 CRITICAL | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
| CVE-2026-18753 | 9.1 CRITICAL | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
No comments yet