CVE-2026-42370
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: 0df08a0e-a200-4957-9bb0-084f562506f9 — https://www.geovision.com.tw/cyber_security.php
References
CWEs
CWE-787
Verify integrity in audit chain (admin only). AS-IS.