CVE-2026-7841: GV-ASWeb Remote Code Execution (RCE) vulnerability
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-ASWeb ASMAnagerto a version that resolves this vulnerability.Fixed in 6.3.0 - Configuration
Disable or restrict access to the Notification Settings endpoint (authenticated user with System Setting permissions) to prevent crafted HTTP POST requests reaching the ASWebCommon.srf backend.
GeoVision GV-ASWeb Notification Settings frontend restrictions / endpoint availability for authenticated users with System Setting permissions = disabled - Compensating control
Implement an external compensating control to block inbound traffic paths that could reach the ASWebCommon.srf backend (e.g., network-level ACL/WAF rules targeting the crafted HTTP POST request behavior), especially for users who only need normal access.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7841?
CVE-2026-7841 is classified as a high severity remote code execution vulnerability.
How do I fix CVE-2026-7841?
To fix CVE-2026-7841, update the GeoVision GV-ASWeb software to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-7841?
CVE-2026-7841 affects GeoVision GV-ASWeb version 6.2.0.
Who can exploit CVE-2026-7841?
An authenticated user with System Setting permissions can exploit CVE-2026-7841 to execute arbitrary commands on the server.
What is the attack vector for CVE-2026-7841?
The attack vector for CVE-2026-7841 involves sending a crafted HTTP POST request to the Notification Settings of the affected system.