CVE-2026-42363Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-656

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-05-23); latest day: 1
  • 12 total mentions across 4 days

Deep dive

Activity timeline12 mentions / 4d
02457Mentions · 2026-04-27: 3Mentions · 2026-04-30: 1Mentions · 2026-05-23: 7Mentions · 2026-10-07: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-30: 1Technical Details · 2026-05-23: 604-2704-3005-2310-07
Signal classification2 categories
Disclosure
981.8%
General
218.2%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure2General1
2026-04-301
Disclosure1
2026-05-237
Disclosure6General1
Full discourse12 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On April 27, 2026, CVE-2026-42363 was published detailing a critical insufficient encryption flaw in GeoVision's Device Authentication subsystem. When administrators interact with GeoVision IP cameras, DVRs, or NVRs using the utility, the software broadcasts…

    Post summary

    The announcement details CVE-2026-42363 as a critical insufficient encryption flaw in GeoVision device authentication, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000041
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: What Happened On April 27, 2026, CVE-2026-42363 was published detailing a critical insufficient encryption flaw in GeoVision's Device Authentication subsystem. When administrators interact with GeoVision IP cameras, DVRs, or…

    Post summary

    CVE-2026-42363, a critical insufficient encryption flaw in GeoVision's Device Authentication subsystem, was publicly released on April 27 2026 with technical details, but no PoC, exploit, or patch information is provided.

    1000042
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42363 · 9.0.5 TL;DR GeoVision GV-IP Device Utility 9.0.5 broadcasts admin credentials in UDP packets with encryption keys included in the same packet.

    Post summary

    This report announces that GeoVision GV-IP Device Utility v9.0.5 exposes admin credentials and encryption keys via UDP broadcasts, constituting a data disclosure vulnerability.

    1000043
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources The Hacker Wire – Critical Credential Leak in GeoVision GV-IP Device Utility THREATINT CVE Database – CVE-2026-42363 TL;DR CVE-2026-42363 (CVSS 9.3) exposes GeoVision device credentials over broadcast UDP packets with the encryption key included in the same message.

    Post summary

    The post reports a newly discovered CVE‑2026‑42363 that exposes GeoVision device credentials via broadcast UDP, highlighting high severity but offering no exploits, patches, or evidence of active attacks.

    1000059
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CVE-2026-42363 (CVSS 9.3) exposes GeoVision device credentials over broadcast UDP packets with the encryption key included in the same message. Any attacker on your LAN can intercept admin credentials and seize full control of cameras, access control systems, and…

    Post summary

    This post discloses a high‑severity vulnerability (CVSS 9.3) in GeoVision devices that leaks admin credentials over broadcast UDP packets, enabling local attackers to take control of cameras and access control systems.

    1000042
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    27, 2026, — The Broadcast Skeleton Key: GeoVision''s Broken Device Authentication Exposes Every IP Camera on Your LAN. TL;DR CVE-2026-42363 (CVSS 9.3) exposes GeoVision device credentials over broadcast UDP packets with the encryption key included in the same message.

    Post summary

    The post announces a new critical vulnerability (CVE-2026-42363) in GeoVision IP cameras that exposes authentication credentials over broadcast UDP packets; no PoC or exploitation details are provided.

    1000049
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42363 An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can… https://www.cve.org/CVERecord?id=CVE-2026-42363

    Post summary

    The note identifies an insufficient encryption issue in GeoVision GV-IP Device Utility 9.0.5 but offers no exploit, PoC, or mitigation details.

    00010126
    57.3K followersView on X
  • CISO Marketplace@CisoMarketplace

    GeoVision camera credentials can be decrypted from a single UDP broadcast packet — no password theft needed. CVSS 9.3, CVE-2026-42363 & CVE-2026-7161, per SentinelOne. Patch guide for estate security teams: https://secureiot.house/geovision-udp-credential-leak-full-mitigation-guide-estate-camera-systems/ #IoTSecurity #CVE https://t.co/kju1TerCas

    0000052
    375 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-04-27-geovision-cve-2026-42363-credential-broadcast #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet shares a link to a research article about CVE-2026-42363 with a zero‑day tag, but it does not provide explicit details on PoC, exploitation, or mitigation. No other actionable indicators are present in the text.

    0000028
    227 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 CRITICAL: CVE-2026-42363 (CVSS 9.3) GeoVision GV-IP Device Utility 9[.]0[.]5 leaks credentials via broadcast packets using weak encryption. Attackers on same LAN can decrypt admin credentials & take full device control. #CVE #Vulnerability #PatchNow https://t.co/VPaNlVNHAD

    Post summary

    The tweet announces a critical credential leakage flaw in GeoVision’s GV-IP Device Utility, describing how attackers on the same LAN could decrypt admin credentials for full device takeover.

    0000044
    11 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-42363 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42363 #CVE-2026-42363 #CVE #Critical #CyberSecurity #InfoSec https://t.co/aSK6D6LbOF

    Post summary

    A new CVE-2026-42363 is announced with a 9.3 severity and critical risk, but the tweet lacks technical details, patch information, or exploitation evidence.

    0000046
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42363 Insufficient Encryption in GeoVision GV-IP Device Utility 9.0.5 Credential Leakage https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42363

    Post summary

    The message announces a new vulnerability (CVE‑2026‑42363) in GeoVision GV‑IP Device Utility 9.0.5, detailing insufficient encryption leading to credential leakage, but provides no PoC, exploit, active usage, or patch information.

    0000048
    4.0K followersView on X

Explore more