Executive brief
GeoVision GV-ASWeb, a web-based access control management interface, contains a security flaw in its notification settings. An attacker with basic system permissions can bypass security restrictions to execute unauthorized commands on the server. This could lead to a complete takeover of the management system, potentially compromising physical security controls and sensitive facility data.
Technical details
A remote code execution (RCE) vulnerability exists in GeoVision GV-ASWeb version 6.2.0 due to improper input validation in the Notification Settings component. The flaw allows an authenticated user with 'System Setting' permissions to bypass frontend security restrictions by sending a specially crafted HTTP POST request directly to the ASWebCommon.srf backend endpoint. This is classified as a code injection vulnerability (CWE-94), enabling the execution of arbitrary system commands with the privileges of the web service. A patch is typically available through GeoVision's standard software update channels.
Affected products
- GeoVision GV-ASWeb 6.2.0
Timeline
- 2026-05-04: advisory: Vendor advisory published by GeoVision
- 2026-05-06: disclosed: CVE published to NVD