Executive brief
GeoWebPlayer, a component used with GeoVision video management software to enable web-based viewing, contains a security flaw that allows unauthorized access to its internal communication server. By tricking a user into visiting a malicious website, an attacker can remotely capture and view the user's screen. This could lead to the theft of sensitive information displayed on the monitor or the compromise of private video surveillance feeds.
Technical details
A missing authentication vulnerability (CWE-306) exists in the WebSocket server functionality of GeoVision GeoWebPlayer (also known as Web Plugin or WS Player). The server, which typically listens on localhost:9100, does not require authentication for incoming connections. A remote attacker can exploit this by hosting a malicious webpage that, when visited by a user with the plugin installed, initiates a WebSocket connection to the local server. By calling a sequence of the 'create' and 'getScreenCapture' methods, the attacker can bypass Same-Origin Policy (SOP) protections and exfiltrate real-time screenshots of the user's desktop. The vulnerability is fixed in version V1.1.3.0.
Affected products
- GeoVision Inc. GeoWebPlayer (Web Plugin / WS Player) V1.1.1.0
Timeline
- 2026-03-25: other: Initial vendor contact
- 2026-04-21: disclosed: Vendor disclosure
- 2026-04-28: patched: Vendor patch release (V1.1.3.0)
- 2026-07-01: advisory: Public release by Cisco Talos
- 2026-07-02: disclosed: NVD publication