Junglewise Threat Intelligence

CVE-2026-12850: GeoVision GV-I/O Box 4E command injection in libNetSetObj.so

CVE-2026-12850 · Severity: critical · CVSS 9.1 · Published 2026-06-24

Technologies: Geovision GV-I/O Box 4E. Vendors: Geovision.

Executive brief

GeoVision GV-I/O Box 4E, a device used to control industrial inputs and relays over a network, contains a critical security flaw in its network configuration library. An attacker can exploit this to take full control of the device by injecting malicious commands through network requests. This could allow an unauthorized user to disrupt operations, manipulate connected hardware, or use the device as a foothold in the corporate network.

Technical details

Multiple OS command injection vulnerabilities exist within the `libNetSetObj.so` library of the GeoVision GV-I/O Box 4E. Specifically, the `CNetSetObj::m_F_n_Set_Gate_way` function fails to sanitize the gateway address string before passing it to a `system()` call via `sprintf`. This vulnerability is reachable via the network-exposed `DVRSearch` service and the `Network.cgi` endpoint. An attacker with high privileges can send a crafted network request to execute arbitrary shell commands with the privileges of the affected process. The vendor has released version 2.12 to address these issues.

Affected products

  • GeoVision GV-I/O Box 4E 2.09

Timeline

  • 2026-04-21: disclosed: Initial vendor contact and disclosure by Cisco Talos
  • 2026-04-28: patched: Vendor patch release (v2.12)
  • 2026-06-24: advisory: Public advisory and CVE publication

References

Related threats