CVE-2026-7841: GeoVision Inc Asmanager
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.
Affected products
- GeoVision Inc Asmanager: version V6.2.0 only
Published 2026-05-06. Last modified 2026-06-17.