PT-2026-51657 · Geovision · Gv-I/O Box 4E
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-I/O Box 4E (affected versions not specified)
Description
The DVRSearch service, which runs by default and listens for UDP messages on port 10001, contains a stack-based buffer overflow. The issue occurs when the server processes unauthenticated network messages and uses an attacker-controlled
net mask length in a memcpy() function to copy data into a fixed-size reply buffer without proper bounds checking. This can be exploited remotely to achieve remote code execution and full device compromise.Recommendations
Disable or block UDP port 10001 at the network perimeter to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-I/O Box 4E