Executive brief
GeoWebPlayer is a software plugin used with GeoVision video management systems to enable web-based video playback and communication features. A security vulnerability in this plugin allows an attacker to potentially take control of a user's computer if the user visits a malicious website. This could lead to unauthorized access to surveillance data, system outages, or the theft of sensitive information.
Technical details
An out-of-bounds read/write vulnerability exists in the WebSocket server component of GeoVision GeoWebPlayer version 1.1.1.0. The '2wayAudio' command fails to validate the 'index' field provided in the JSON payload before using it to access internal arrays. An attacker can exploit this by hosting a malicious webpage that sends a specially crafted WebSocket message to the local GeoWebPlayer service. This can result in the execution of arbitrary code via an out-of-bounds function pointer call or memory corruption. The vulnerability is addressed in version 1.1.3.0.
Affected products
- GeoVision Inc. GeoWebPlayer 1.1.1.0
Timeline
- 2026-07-01: disclosed: Initial discovery by Cisco Talos
- 2026-07-02: advisory: NVD publication date
- 2026-07-02: patched: Version 1.1.3.0 listed as unaffected/fixed