Executive brief
GeoVision GeoWebPlayer, a plugin used to facilitate web-based video management and camera viewing, contains a security vulnerability in how it handles connection information. An attacker could exploit this by tricking a user into visiting a malicious webpage, potentially allowing the attacker to take control of the user's system or disrupt video surveillance operations. This affects organizations using GeoVision VMS or Cloud solutions that rely on this web plugin for camera connectivity.
Technical details
GeoVision GeoWebPlayer version 1.1.1.0 contains a stack-based buffer overflow vulnerability (CWE-120) within the 'handle_connection_info' function of its WebSocket server. The vulnerability arises when the server processes a 'connectionInfo' command; it copies the 'ip' field from an attacker-controlled JSON string into a fixed-size 256-byte buffer (conn_info.ip_or_host) using a manual byte-by-byte loop without length validation. While the WebSocket server listens on localhost, the attack vector is remote via a malicious webpage (User Interaction required) that communicates with the local WebSocket server. Successful exploitation can lead to arbitrary code execution with the privileges of the GeoWebPlayer process. The vendor has released version 1.1.3.0 to address this issue.
Affected products
- GeoVision Inc. GeoWebPlayer V1.1.1.0
Timeline
- 2026-03-25: other: Initial vendor contact
- 2026-04-21: disclosed: Vendor disclosure
- 2026-04-28: patched: Vendor patch release (V1.1.3.0)
- 2026-07-01: advisory: Public release by Talos
- 2026-07-02: advisory: NVD publication