CVE-2026-42363: GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

Published Apr 26, 2026
·
Updated

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability.

When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.

Affected Software

1 affected component
GeoVision GV-IP Device Utility=9.0.5

Remediation

Information

GeoVision GV-IP Device Utility Device Authentication version 9.0.7.0 has patched reported vulnerability.

Event History

Apr 26, 2026
CVE Published
via MITRE·11:58 PM
Data Sourced
via MITRE·11:58 PM
RemedyDescriptionSeverityWeakness
Apr 27, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42363?

CVE-2026-42363 is classified as a medium severity vulnerability due to potential credential leaks.

2

How do I fix CVE-2026-42363?

To mitigate CVE-2026-42363, update the GeoVision GV-IP Device Utility software to the latest version that addresses this vulnerability.

3

What does CVE-2026-42363 affect?

CVE-2026-42363 affects version 9.0.5 of the GeoVision GV-IP Device Utility.

4

What kind of attack does CVE-2026-42363 expose users to?

CVE-2026-42363 allows attackers to listen to broadcast packets, potentially leading to a credential leak.

5

Is CVE-2026-42363 a remote or local vulnerability?

CVE-2026-42363 can be exploited remotely through broadcast packet interception.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203