CVE-2026-42370: GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerability
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-VMS V20to a version that resolves this vulnerability.Fixed in V20.1.0 - Upgrade
Upgrade
GeoVision GV-VMS V20.0.2to a version that resolves this vulnerability.Fixed in V20.0.2.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42370?
CVE-2026-42370 has a critical severity level due to its potential for arbitrary code execution.
How do I fix CVE-2026-42370?
To fix CVE-2026-42370, update GeoVision GV-VMS to version 20.0.3 or later.
What software is affected by CVE-2026-42370?
CVE-2026-42370 affects GeoVision GV-VMS V20 version 20.0.2.
What type of vulnerability is CVE-2026-42370?
CVE-2026-42370 is a stack overflow vulnerability in the WebCam Server Login functionality.
Can CVE-2026-42370 be exploited remotely?
Yes, CVE-2026-42370 can be exploited remotely through a specially crafted HTTP request.