Executive brief
A security vulnerability exists in the GeoVision GV-IP Device Utility, a tool used to manage and configure GeoVision IP cameras and surveillance hardware. When an administrator uses the utility to send commands, the software transmits sensitive login credentials over the local network using weak encryption that includes the decryption key within the message itself. An attacker on the same local network can intercept these messages to steal usernames and passwords, potentially gaining full control over the security cameras, including the ability to change settings or reset devices to factory defaults.
Technical details
An insufficient encryption vulnerability (CWE-656) exists in GeoVision GV-IP Device Utility 9.0.5. When the utility sends privileged commands to devices, it broadcasts UDP packets containing the username and password. While the credentials are encrypted using a protocol derived from Blowfish, the symmetric encryption key is included within the same packet. An attacker on the same LAN can capture this broadcast traffic, extract the key, and decrypt the credentials. This allows for unauthorized administrative access to GeoVision devices, enabling attackers to modify IP configurations or perform factory resets. The vulnerability is triggered when an authenticated user interacts with the device via the utility.
Affected products
- GeoVision GV-IP Device Utility 9.0.5
Timeline
- 2026-04-27: advisory: NVD and vendor advisory published