GeoVision GV-VMS是中国GeoVision公司的一款视频管理系统软件。 GeoVision GV-VMS V20 20.0.2版本存在缓冲区错误漏洞,该漏洞源于WebCam Server登录功能中栈溢出,可能导致特制HTTP请求导致任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-VMS V20.0.2 | 20.0.2 |
affected |
20.0.2.10 |
unaffected | ||
20.1.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-VMS V20.0.2 | 20.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42369 | 10.0 CRITICAL | GeoVision GV-VMS V20 WebCam Server stack overflow vulnerability |
| CVE-2026-42368 | 9.9 CRITICAL | GeoVision LPC2011/LPC2211 Web Interface privilege escalation vulnerability |
| CVE-2026-42364 | 9.9 CRITICAL | GeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerabili |
| CVE-2026-7161 | 9.3 CRITICAL | GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability |
| CVE-2026-7372 | 9.0 CRITICAL | GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerability |
| CVE-2026-42365 | 8.6 HIGH | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability |
| CVE-2026-42366 | 7.4 HIGH | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vul |
| CVE-2026-7371 | 7.4 HIGH | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vul |
| CVE-2026-42367 | 6.5 MEDIUM | GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via l |
No comments yet