Junglewise Threat Intelligence

CVE-2026-7161: GeoVision GV-IP Device Utility insufficient encryption in Device Authentication

CVE-2026-7161 · Severity: critical · CVSS 9.3 · Published 2026-05-04

Technologies: Geovision GV-IP Device Utility. Vendors: Geovision.

Executive brief

GeoVision GV-IP Device Utility is a tool used to manage and configure GeoVision security cameras and devices on a local network. A security flaw allows an attacker on the same network to intercept administrative credentials because they are sent with weak encryption that includes the decryption key in the same message. If exploited, an attacker could gain full control over security cameras, allowing them to change settings, view feeds, or reset devices to factory defaults.

Technical details

An insufficient encryption vulnerability (CWE-656) exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. When the utility sends privileged commands to devices via UDP broadcast, it encrypts the username and password using a Blowfish-derived protocol; however, the symmetric encryption key is included within the same packet. An attacker on the same local area network (LAN) can sniff this broadcast traffic and decrypt the credentials. Successful exploitation provides the attacker with administrative access to the device configuration, enabling actions such as IP address modification or factory resets.

Affected products

  • GeoVision GV-IP Device Utility 9.0.5

Timeline

  • 2026-04-27: advisory: Vendor security advisory published
  • 2026-05-04: disclosed: NVD publication date
  • 2026-06-15: other: Talos vulnerability report published

References

Related threats