CVE-2026-7161: GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

Published May 4, 2026
·
Updated

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability.

When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.

Affected Software

2 affected components
GeoVision GV-IP Device Utility=9.0.5
GeoVision GV-IP Device Utility=9.0.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GeoVision GV-IP Device Utility to a version that resolves this vulnerability.

    Fixed in 9.0.7.0
  2. Compensating control

    To reduce the risk of credential leakage via broadcast UDP packets on the same LAN, restrict network access/segmentation so that untrusted hosts cannot listen to GeoVision GV-IP Device Utility broadcast traffic (e.g., limit access to the relevant ports/subnets/firewall rules).

Event History

May 4, 2026
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software
Mar 29, 58312
Event
via FIRST·11:43 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-7161?

CVE-2026-7161 is considered a critical vulnerability due to insufficient encryption in device authentication.

2

How do I fix CVE-2026-7161?

To mitigate CVE-2026-7161, update the GeoVision GV-IP Device Utility to a patched version that addresses the insufficient encryption issue.

3

What is the impact of CVE-2026-7161?

The impact of CVE-2026-7161 includes potential credential leaks through intercepted broadcast packets.

4

Which version of GeoVision is affected by CVE-2026-7161?

CVE-2026-7161 affects GeoVision GV-IP Device Utility version 9.0.5.

5

What can an attacker do with CVE-2026-7161?

An attacker can exploit CVE-2026-7161 to listen to broadcast packets and potentially gain unauthorized access to device credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203