Executive brief
GeoWebPlayer is a browser-based plugin used to view video feeds from GeoVision surveillance systems. A security flaw allows an attacker to create a malicious website that, if visited by a user, can take control of the plugin to execute unauthorized commands. This could lead to the attacker gaining control over the user's computer or disrupting the surveillance software's operations.
Technical details
An out-of-bounds read vulnerability exists in the WebSocket server component of GeoVision GeoWebPlayer (also known as Web Plugin or WS Player). The 'setPIP' command fails to validate the 'index' field provided in WebSocket messages before using it to access internal arrays. An attacker can exploit this by hosting a malicious webpage that sends a specially crafted WebSocket message to the local server. This results in the application reading a function pointer out-of-bounds, which can be leveraged to achieve arbitrary code execution. The vulnerability is confirmed in version 1.1.1.0 and is addressed in version 1.1.3.0.
Affected products
- GeoVision Inc. GeoWebPlayer (Web Plugin / WS Player) 1.1.1.0
Timeline
- 2026-07-01: disclosed: Initial disclosure by Cisco Talos
- 2026-07-02: advisory: NVD publication date
- 2026-07-02: patched: Version 1.1.3.0 listed as unaffected/fixed