Junglewise Threat Intelligence

CVE-2026-12851: GeoVision GV-I/O Box 4E command injection in libNetSetObj.so

CVE-2026-12851 · Severity: critical · CVSS 9.1 · Published 2026-06-24

Technologies: Geovision GV-I/O Box 4E. Vendors: Geovision.

Executive brief

GeoVision GV-I/O Box 4E is an Ethernet-based device used to control physical inputs and relays for security and automation systems. A security flaw in its network configuration library allows an attacker to take full control of the device by sending a malicious network request. This could lead to unauthorized manipulation of physical security hardware or a complete service outage.

Technical details

Multiple OS command injection vulnerabilities exist within the `libNetSetObj.so` library of the GeoVision GV-I/O Box 4E firmware version 2.09. The root cause is a failure to sanitize user-supplied input in functions such as `CNetSetObj::m_F_n_Set_DNS_Addr`, `m_F_n_Set_IP_Addr`, `m_F_n_Set_Net_Mask`, and `m_F_n_Set_Gate_way` before passing them to the `system()` function. These functions are reachable via the network-exposed `DVRSearch` service and the `Network.cgi` web endpoint. An attacker with high privileges can exploit these flaws by sending specially crafted network packets to execute arbitrary system commands with root privileges. A patch was released by the vendor on 2026-04-28 (likely version 2.12).

Affected products

  • GeoVision GV-I/O Box 4E 2.09

Timeline

  • 2026-04-21: disclosed: Initial vendor contact and disclosure by Cisco Talos
  • 2026-04-28: patched: Vendor patch release
  • 2026-06-23: advisory: Cisco Talos advisory published
  • 2026-06-24: advisory: NVD publication date

References

Related threats