PT-2026-51662 · Geovision · Gv-I/O Box 4E
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-I/O Box 4E version 2.09
Description
OS command injection flaws exist in the
libNetSetObj.so internal library, which is used to configure the network stack. A remote attacker can execute arbitrary commands by sending a specially crafted network packet. The CNetSetObj::m F n Set DNS Addr() function fails to sanitize input before passing it to the system call. This issue is reachable via the Network.cgi endpoint and the DVRSearch service. The vulnerable parameters are dns1 and dns2.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-I/O Box 4E