Junglewise Threat Intelligence

CVE-2026-12488: GeoVision GV-VMS stack buffer overflow in GV-Cloud

CVE-2026-12488 · Severity: medium · CVSS 6.2 · Published 2026-06-24

Technologies: Geovision GV-VMS. Vendors: Geovision.

Executive brief

A security vulnerability exists in GeoVision's video management software, which is used to manage and monitor security camera feeds. An attacker could impersonate a legitimate cloud server to send malicious commands to the software, potentially causing the system to crash or stop responding. This could lead to a temporary loss of surveillance capabilities and security monitoring.

Technical details

A stack-based buffer overflow (CWE-121) exists in the GvRelayProxy.dll component of GeoVision GV-VMS V20. The vulnerability is located in the GvRelayProxyServerThreadProc function, which fails to validate the 'size' field in the header of incoming network messages before reading data into a fixed-size stack buffer (4072 bytes). An attacker can exploit this by impersonating the 'relay.vsm.mygvcloud.com' server via DNS poisoning or Man-in-the-Middle (MitM) attacks, as the software fails to properly verify the server's identity during the handshake. Successful exploitation can lead to a denial of service (DoS) via a stack cookie failure or potentially remote code execution (RCE) if the attacker can bypass stack protections. The issue is addressed in version 20.1.0.0.

Affected products

  • GeoVision GV-VMS V20 20.0.2

Timeline

  • 2025-12-02: patched: Vendor released version 20.1.0.0 to address the issue.
  • 2026-05-10: disclosed: Vulnerability disclosed to the vendor.
  • 2026-06-23: advisory: Cisco Talos published detailed vulnerability report.
  • 2026-06-24: disclosed: CVE-2026-12488 published.

References

Related threats