CVE-2026-7841: GeoVision Inc Asmanager

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.

Affected products

Published 2026-05-06. Last modified 2026-06-17.