PT-2026-51659 · Geovision · Gv-I/O Box 4E

·

CVE-2026-12848

·

Published

2026-06-24

·

Updated

2026-07-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoVision GV-I/O Box 4E (affected versions not specified)
Description The DVRSearch service, which runs by default and listens for UDP messages on port 10001, contains a stack-based buffer overflow. The issue occurs when the server reads up to 1460 bytes into a local buffer and subsequently performs an unsafe copy of the configured DNS address into a reply buffer using memcpy() with a length derived from strlen(). An unauthenticated network attacker can send crafted UDP traffic to trigger this overflow, potentially leading to remote code execution and full compromise of confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12848

Affected Products

Gv-I/O Box 4E