Lyrie.ai[verified]@lyrie_aiDisclosure
The announcement details CVE-2026-42363 as a critical insufficient encryption flaw in GeoVision device authentication, but provides no PoC, exploit, patch, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
CVE-2026-42363, a critical insufficient encryption flaw in GeoVision's Device Authentication subsystem, was publicly released on April 27 2026 with technical details, but no PoC, exploit, or patch information is provided.
Lyrie.ai[verified]@lyrie_aiDisclosure
This report announces that GeoVision GV-IP Device Utility v9.0.5 exposes admin credentials and encryption keys via UDP broadcasts, constituting a data disclosure vulnerability.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post reports a newly discovered CVE‑2026‑42363 that exposes GeoVision device credentials via broadcast UDP, highlighting high severity but offering no exploits, patches, or evidence of active attacks.
Lyrie.ai[verified]@lyrie_aiDisclosure
This post discloses a high‑severity vulnerability (CVSS 9.3) in GeoVision devices that leaks admin credentials over broadcast UDP packets, enabling local attackers to take control of cameras and access control systems.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a new critical vulnerability (CVE-2026-42363) in GeoVision IP cameras that exposes authentication credentials over broadcast UDP packets; no PoC or exploitation details are provided.
Lyrie.ai[verified]@lyrie_aiGeneral
The tweet shares a link to a research article about CVE-2026-42363 with a zero‑day tag, but it does not provide explicit details on PoC, exploitation, or mitigation. No other actionable indicators are present in the text.
DFIR Lab[verified]@DFIR_LabDisclosure
The tweet announces a critical credential leakage flaw in GeoVision’s GV-IP Device Utility, describing how attackers on the same LAN could decrypt admin credentials for full device takeover.