CVE Explorer
CVE-2026-42369
GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and monitoring feature via a regular Web interface. This webersever is another native application, compiled without ASLR, which makes exploitation much easier and more likely.
Most
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Windows"],"product":"GV-VMS V20.0.2","vendor":"GeoVision Inc.","versions":[{"status":"affected","version":"V20.0.2"},{"status":"unaffected","version":"V20.0.2.10"},{"status":"unaffected","version":"V20.1.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:430689918e44b63597757d9b13b3d0f5ae006a53e99409e769c7c9bbc363b6ae · sha256:959773c63a0e1af3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:430689918e44b63597757d9b13b3d0f5ae006a53e99409e769c7c9bbc363b6ae · sha256:959773c63a0e1af3… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-787","description":"CWE-787 Out-of-bounds write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:430689918e44b63597757d9b13b3d0f5ae006a53e99409e769c7c9bbc363b6ae · sha256:959773c63a0e1af3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://https://talosintelligence.com/vulnerability_reports/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:430689918e44b63597757d9b13b3d0f5ae006a53e99409e769c7c9bbc363b6ae · sha256:959773c63a0e1af3… · /containers/cna/references/1
{"tags":["vendor-advisory","third-party-advisory"],"url":"https://www.geovision.com.tw/cyber_security.php"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:430689918e44b63597757d9b13b3d0f5ae006a53e99409e769c7c9bbc363b6ae · sha256:959773c63a0e1af3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.