CVE-2026-12846Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP messages on port 10001. Any user on the network can send messages to this service and interact with it. Upon receiving a UDP message, the server reads at most 1460 bytes into a local buffer and a pointer to the buffer is stored in a global variable: #### Net Mask field stack overflow The following code is vulnerable to a stack overflow that is attacker-controlled: v6 = strlen(g_network_config->net_mask); memcpy(&reply_buf[184], g_network_config->net_mask, v6);

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-24); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-24: 1Mentions · 2026-06-27: 1Mentions · 2026-07-03: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-03: 106-2406-2707-03
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-241
Disclosure1
2026-06-271
Disclosure1
2026-07-031
General1
Full discourse3 posts
  • Kaitan ID Security@KaitanSecurity
    General

    🛡️ GeoVision Hardware: Four Critical IoT Flaws The GV-I/O Box 4E smart I/O device accumulated four simultaneous CVSS 10.0 vulnerabilities: CVE-2026-12485, CVE-2026-12846, CVE-2026-12847, and CVE-2026-12848. These devices…

    Post summary

    The post announces four CVSS 10.0 critical vulnerabilities (CVE-2026-12485, CVE-2026-12846, CVE-2026-12847, CVE-2026-12848) in GeoVision GV‑I/O Box 4E devices but provides no details on exploitation or remediation.

    1000045
    84 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - GeoVision GV-I/O Box 4E DVRSearch UDP stack buffer overflow (CVE-2026-12846) GeoVision GV-I/O Box 4E exposes a default UDP discovery/service endpoint (DVRSearch) on port 10001 that processes unauthenticated network messages. The flaw is a stack-based buffer overflow caused by improper bounds checking where an attacker-controlled net_mask length is used in a memcpy into a fixed-size reply buffer. An attacker can exploit this remotely over the network by sending a crafted UDP request to port 10001 with no credentials required. Successful exploitation can lead to full device compromise, including remote code execution and complete loss of confidentiality, integrity, and availability. 👉 Affected: GeoVision GV-I/O Box 4E (versions unknown; default DVRSearch UDP service on 10001) | Upgrade to vendor-fixed firmware (not yet specified) or disable/block UDP 10001 at the perimeter immediately

    Post summary

    The advisory announces a critical stack buffer overflow in GeoVision’s DVRSearch UDP service, capable of remote code execution, and recommends disabling UDP port 10001 or applying vendor firmware updates.

    0001068
    226 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    📡 CVE-2026-12846: CVSS 10 buffer overflow in GeoVision GV-I/O Box 4E. The DVRSearch service accepts unauthenticated UDP — no auth, no interaction needed for full compromise. Reported by Talos. Check your network edge devices. #ICS #IoT https://secalerts.co/vulnerability/CVE-2026-12846?utm_campaign=x https://t.co/LNRycG2sGr

    Post summary

    The tweet announces a new high‑severity CVE‑2026‑12846 affecting GeoVision GV‑I/O Box 4E, provides key technical details, and warns users to review network edge devices. No PoC, exploit, or patch information is disclosed.

    0000091
    845 followersView on X

Explore more