Junglewise Threat Intelligence

CVE-2026-42369: GeoVision GV-VMS stack overflow in gvapi endpoint

CVE-2026-42369 · Severity: critical · CVSS 10 · Published 2026-05-04

Technologies: Geovision GV-VMS. Vendors: Geovision.

Executive brief

GeoVision GV-VMS is a video management system used to monitor surveillance camera feeds and manage security hardware. A critical vulnerability in its remote access feature allows an attacker to take complete control of the server hosting the software. This could lead to the total loss of surveillance data, unauthorized access to live camera feeds, and a foothold for further attacks on the corporate network.

Technical details

A stack-based buffer overflow exists in the 'gvapi' endpoint of GeoVision GV-VMS V20 when the WebCam Server feature is enabled. The vulnerability is located in the handling of the HTTP Authorization header, which supports Basic and Digest authentication. A base64-decoded string is copied into a fixed-size 256-byte stack buffer without adequate bounds checking. Because the web server component is compiled without Address Space Layout Randomization (ASLR), an unauthenticated remote attacker can reliably exploit this overflow to overwrite the return address and achieve arbitrary code execution with SYSTEM privileges.

Affected products

  • GeoVision GV-VMS V20

Timeline

  • 2026-04-27: advisory: Vendor published security advisory GV-VMS-2026-04-01
  • 2026-05-04: disclosed: NVD publication date

References

Related threats