TopVuln

High-risk vulnerability digests

CVE-2026-42370

  • CRITICAL

Details

CVSS v3
9.0
NVD published
2026-05-04 01:16:04
EPSS
0.2% probability · 45.6th percentile — 2026-05-12
Affected versions
GeoVision GV-VMS V20 20.0.2
Summary
A stack overflow vulnerability exists in the WebCam Server login functionality of GeoVision GV-VMS V20. Unauthenticated remote attackers can trigger the vulnerability by sending a specially crafted HTTP request to the affected service. Successful exploitation allows attackers to achieve arbitrary code execution on the affected surveillance system.
Remediation
Upgrade GeoVision GV-VMS V20 to the latest vendor-patched version as soon as possible. Block incoming connections to the WebCam Server from untrusted public networks. Audit system logs for any suspicious activity on affected deployments until remediation is complete.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.