Executive brief
GeoVision GV-I/O Box 4E is an Ethernet-based device used to control physical inputs and relays for security and automation systems. A security flaw in its network configuration library allows an attacker to take full control of the device by sending a malicious network request. This could lead to unauthorized manipulation of physical security hardware or a complete service outage.
Technical details
Multiple OS command injection vulnerabilities exist within the `libNetSetObj.so` library of the GeoVision GV-I/O Box 4E firmware version 2.09. The root cause is a failure to sanitize user-supplied input in functions such as `CNetSetObj::m_F_n_Set_DNS_Addr`, `m_F_n_Set_IP_Addr`, `m_F_n_Set_Net_Mask`, and `m_F_n_Set_Gate_way` before passing them to the `system()` function. These functions are reachable via the network-exposed `DVRSearch` service and the `Network.cgi` web endpoint. An attacker with high privileges can exploit these flaws by sending specially crafted network packets to execute arbitrary system commands with root privileges. A patch was released by the vendor on 2026-04-28 (likely version 2.12).
Affected products
- GeoVision GV-I/O Box 4E 2.09
Timeline
- 2026-04-21: disclosed: Initial vendor contact and disclosure by Cisco Talos
- 2026-04-28: patched: Vendor patch release
- 2026-06-23: advisory: Cisco Talos advisory published
- 2026-06-24: advisory: NVD publication date