Executive brief
GeoVision GV-IP Device Utility is a tool used to manage and configure GeoVision security cameras and devices on a local network. A security flaw allows an attacker on the same network to intercept administrative credentials because they are sent with weak encryption that includes the decryption key in the same message. If exploited, an attacker could gain full control over security cameras, allowing them to change settings, view feeds, or reset devices to factory defaults.
Technical details
An insufficient encryption vulnerability (CWE-656) exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. When the utility sends privileged commands to devices via UDP broadcast, it encrypts the username and password using a Blowfish-derived protocol; however, the symmetric encryption key is included within the same packet. An attacker on the same local area network (LAN) can sniff this broadcast traffic and decrypt the credentials. Successful exploitation provides the attacker with administrative access to the device configuration, enabling actions such as IP address modification or factory resets.
Affected products
- GeoVision GV-IP Device Utility 9.0.5
Timeline
- 2026-04-27: advisory: Vendor security advisory published
- 2026-05-04: disclosed: NVD publication date
- 2026-06-15: other: Talos vulnerability report published