Junglewise Threat Intelligence

CVE-2026-7841: GeoVision GV-ASWeb remote code execution in Notification Settings

CVE-2026-7841 · Severity: high · CVSS 8.8 · Published 2026-05-06

Vendors: Geovision.

Executive brief

GeoVision GV-ASWeb, a web-based access control management interface, contains a security flaw in its notification settings. An attacker with basic system permissions can bypass security restrictions to execute unauthorized commands on the server. This could lead to a complete takeover of the management system, potentially compromising physical security controls and sensitive facility data.

Technical details

A remote code execution (RCE) vulnerability exists in GeoVision GV-ASWeb version 6.2.0 due to improper input validation in the Notification Settings component. The flaw allows an authenticated user with 'System Setting' permissions to bypass frontend security restrictions by sending a specially crafted HTTP POST request directly to the ASWebCommon.srf backend endpoint. This is classified as a code injection vulnerability (CWE-94), enabling the execution of arbitrary system commands with the privileges of the web service. A patch is typically available through GeoVision's standard software update channels.

Affected products

  • GeoVision GV-ASWeb 6.2.0

Timeline

  • 2026-05-04: advisory: Vendor advisory published by GeoVision
  • 2026-05-06: disclosed: CVE published to NVD

References