CVE-2026-42369Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and monitoring feature via a regular Web interface. This webersever is another native application, compiled without ASLR, which makes exploitation much easier and more likely. Most of the features require authentication before being reachable and leverage a standard login page to grant access. However the `gvapi` endpoint uses its own authentication mechanism via an `HTTP Authorization` header. It supports both `Basic` authentication and the `Digest` modes of authentication.   #### Stack-overflow via unbound copy of base64 decoded string The `b64decoder` string is sized dynamically, but it is then copied to the `Buffer` stack variable one character at the time at [0], and there's no bound-check. As such, if the decoded string is bigger than 256 characters (the size of the `Buffer` variable) then a stack overflow occurs. Because the data can be fully controlled by an attacker and lack of ASLR, this vulnerability can easily be exploited to gain full code execution as SYSTEM on the machine running the service.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 9 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-06-02); latest day: 3
  • 13 total mentions across 5 days

Deep dive

Activity timeline13 mentions / 5d
01345Mentions · 2026-05-04: 2Mentions · 2026-05-13: 2Mentions · 2026-05-15: 1Mentions · 2026-06-02: 5Mentions · 2026-06-17: 3Active Exploitation · 2026-06-02: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-02: 5Technical Details · 2026-06-17: 305-0405-1305-1506-0206-17
Signal classification3 categories
Disclosure
969.2%
General
323.1%
Patch
17.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-132
General2
2026-05-151
Patch1
2026-06-025
Disclosure5
2026-06-173
Disclosure2General1
Full discourse13 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42369 — CVSS 10.0 | GV-VMS V20 WebCam Server gvapi Stack Overflow → SYSTEM RCE On May 4, 2026, researchers published five critical-severity CVEs targeting GeoVision surveillance hardware and video management software.

    Post summary

    Researchers disclosed five critical CVEs, including CVE-2026-42369—a stack overflow that enables SYSTEM RCE in GeoVision surveillance software, rated with CVSS 10.0.

    1000041
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    A close sibling to CVE-2026-42369, this vulnerability targets the login processing logic of the same WebCam Server component in GV-VMS V20 20.0.2 rather than the authenticated gvapi endpoint. The mechanism is identical — an oversized HTTP request during the login process…

    Post summary

    The text outlines an oversized HTTP request vulnerability in the WebCam Server component of GV‑VMS V20 20.0.2, similar to CVE‑2026‑42369, impacting the login processing logic.

    1000045
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Impact vs Product vs CVSS vs Vector: CVE-2026-42369: RCE as SYSTEM (no ASLR) (vs Product GV-VMS V20 | CVSS **10.0** | Vector Remote, Unauth) CVE-2026-42370: RCE via login stack overflow (vs Product GV-VMS V20 20.0.2 | CVSS 9.0 | Vector Remote, Unauth) CVE-2026-42364: OS…

    Post summary

    The excerpt lists three CVEs with RCE details, CVSS scores, and product context, but lacks evidence of PoC, exploit code, active exploitation, patches, or false‑positive claims.

    1000041
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR GeoVision's GV-VMS V20 (Video Monitoring Software) contains a CVSS 10.0 stack overflow vulnerability (CVE-2026-42369) in the WebCam Server feature. Unauthenticated remote attackers can trigger code execution as SYSTEM by sending oversized base64-encoded HTTP…

    Post summary

    The text reports a critical stack overflow flaw (CVE-2026-42369) in GeoVision GV‑VMS V20 that allows unauthenticated remote code execution as SYSTEM.

    1000047
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources TheHackerWire: "GV-VMS V20 Critical RCE via WebCam Server Stack Overflow" ( CVE-2026-42369 Official Details The Surveillance Camera That Became the Backdoor: GV-VMS V20 CVSS 10 Stack Overflow RCE

    Post summary

    The text announces a new critical RCE vulnerability (CVE‑2026‑42369) affecting GV‑VMS V20, describing a stack‑overflow flaw in the webcam server with a CVSS of 10, but provides no PoC, exploit, active exploitation evidence, or patch details.

    1000055
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR GeoVision GV-VMS V20 has a CVSS 10.0 unauthenticated stack overflow RCE in its WebCam Server component (CVE-2026-42369), disclosed today. A companion command injection flaw (CVE-2026-42364) hits network-connected LPC cameras at CVSS 9.9. Both allow remote code…

    Post summary

    GeoVision GV‑VMS V20 has been found to contain two critical unauthenticated flaws—a stack over‑flow RCE (CVSS 10.0) and a command‑injection flaw (CVSS 9.9)—both disclosed today.

    1000043
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 4, 2026, security researchers disclosed CVE-2026-42369, a critical stack overflow vulnerability in GeoVision GV-VMS V20—one of the world's most deployed video management systems. The flaw is in the "WebCam Server" component, which exposes an HTTP interface (gvapi…

    Post summary

    Security researchers announced CVE-2026-42369, a critical stack‑overflow flaw in GeoVision’s GV‑VMS V20 WebCam Server, without providing a PoC, exploit code, or patch details.

    1000043
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Forgotten Camera Just Became a Fortress Breach: GeoVision VMS CVSS 10 RCE Hits Surveillance Infrastructure Worldwide. On May 4, 2026, security researchers disclosed CVE-2026-42369, a critical stack overflow vulnerability in GeoVision GV-VMS V20—one of the world's most…

    Post summary

    Security researchers disclosed CVE-2026-42369, a critical stack overflow RCE in GeoVision VMS, with indications it is being exploited worldwide.

    1000050
    238 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42369 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces a critical advisory for CVE-2026-42369 with a CVSS of 10, but provides no PoC, exploit, patch, or mitigation information.

    1000025
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical stack overflow vulnerability (CVE-2026-42369) affects GV-VMS V20 video monitoring software, potentially allowing attackers full system access. Mohawk Valley organizations using this software should update or disable remote access immediately. #CyberSecurity

    Post summary

    The message highlights a critical stack overflow in GV‑VMS V20, warns that attackers may gain full system access, and urges affected organizations to update or disable remote access to mitigate the risk.

    0000050
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42369-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet simply shares a link to an advisory without providing any further detail about the vulnerability, its exploitation, or remediation.

    0000021
    210 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in GeoVision GV-VMS (CVE-2026-42369) https://vuldb.com/vuln/360931

    Post summary

    A new high‑severity vulnerability, CVE‑2026‑42369, has been disclosed for GeoVision GV‑VMS, with a reference to a VULDB page for additional information.

    0000086
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42369 Stack Overflow in GV-VMS V20 WebCam Server Base64 Decoder Leading to Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42369

    Post summary

    CVE‑2026‑42369 describes a stack overflow in GV‑VMS V20 WebCam Server’s Base64 decoder that can lead to code execution.

    0000062
    4.0K followersView on X

Explore more