CVE-2026-42370: GeoVision Gv-Vms Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

Affected products

  • GeoVision Gv-Vms Firmware: before 21.0.0 (fixed in 21.0.0)

Published 2026-05-04. Last modified 2026-06-17.