Kaitan ID Security[verified]@KaitanSecurityGeneral
The post announces four critical CVSS 10.0 vulnerabilities in GeoVision IoT devices, but provides no details about exploits, patches, or active attacks.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces a critical DVRSearch UDP stack buffer overflow in GV‑I/O Box 4E that allows unauthenticated remote code execution, explains how to trigger it with an overlong IP field, and notes that no vendor patch is yet available.
ExploitGrid@exploitgridExploit
The post lists multiple CVEs labeled with "EXPLOIT", indicating they are considered exploit‑able, but no further details or code are provided.
CCB Alert@CCBalertDisclosure
The post discloses CVE‑2026‑12485 as a critical stack‑overflow vulnerability in GeoVision devices that can be triggered via crafted UDP packets, leading to remote code execution, and hints at a patch being available.
ExploitGrid@exploitgridExploit
An announced critical buffer overflow in GeoVision DVRSearch (CVE‑2026‑12485) now has a publicly available PoC and exploit script on ExploitGrid, with no evidence yet of active exploitation or patch availability.
SecAlerts@SecAlertsCoDisclosure
Talos has disclosed a CVSS 10 buffer overflow in GeoVision GV‑I/O Box 4E that allows unauthenticated UDP exploitation, leading to full system compromise; no patches or PoC information are provided.