PT-2026-51657 · Geovision · Gv-I/O Box 4E

·

CVE-2026-12846

·

Published

2026-06-24

·

Updated

2026-07-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoVision GV-I/O Box 4E (affected versions not specified)
Description The DVRSearch service, which runs by default and listens for UDP messages on port 10001, contains a stack-based buffer overflow. The issue occurs when the server processes unauthenticated network messages and uses an attacker-controlled net mask length in a memcpy() function to copy data into a fixed-size reply buffer without proper bounds checking. This can be exploited remotely to achieve remote code execution and full device compromise.
Recommendations Disable or block UDP port 10001 at the network perimeter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12846

Affected Products

Gv-I/O Box 4E