CVE-2026-42370Disclosure(geovision / gv-vms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch geovision gv-vms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-vms
  • gv-vms_firmware

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-13); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
gv-vmsgv-vms_firmware

1 version affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-05-04: 2Mentions · 2026-05-13: 4Mentions · 2026-05-16: 1Mentions · 2026-06-17: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-13: 3Technical Details · 2026-05-16: 1Technical Details · 2026-06-17: 105-0405-1305-1606-17
Signal classification3 categories
Disclosure
562.5%
General
225.0%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-134
Disclosure3General1
2026-05-161
Patch1
2026-06-171
Disclosure1
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Impact vs Product vs CVSS vs Vector: CVE-2026-42369: RCE as SYSTEM (no ASLR) (vs Product GV-VMS V20 | CVSS **10.0** | Vector Remote, Unauth) CVE-2026-42370: RCE via login stack overflow (vs Product GV-VMS V20 20.0.2 | CVSS 9.0 | Vector Remote, Unauth) CVE-2026-42364: OS…

    Post summary

    The text lists new CVEs with RCE details, high CVSS scores, and remote unauth vectors, but offers no PoC, exploit code, active exploitation evidence, or remediation guidance.

    1000041
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42370 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A validation of CVE-2026-42370 with a CVSS score of 9 is announced as a critical advisory; no PoC, exploit, patch, or false‑positive information is disclosed.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42370 (CVSS 9) — multiple products. CVE: CVE-2026-42370 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This post announces CVE‑2026‑42370, a critical vulnerability with CVSS 9 that affects multiple products, and labels it as a critical advisory.

    1000022
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42370 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2.

    Post summary

    A critical CVE-2026-42370 has been disclosed, describing a stack overflow vulnerability in GeoVision GV-VMS V20 20.0.2’s WebCam Server Login function with a CVSS score of 9.0.

    1000023
    210 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting GeoVision GV-VMS V20.0.2 (CVE-2026-42370) https://vuldb.com/vuln/360930

    Post summary

    A new vulnerability (CVE-2026-42370) affecting GeoVision GV-VMS V20.0.2 has been announced, with a link to additional information on Vuldb.

    0001064
    2.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical stack overflow vulnerability (CVE-2026-42370) in GeoVision GV-VMS V20 20.0.2 allows unauthenticated code execution via HTTP requests. If you use this system, prioritize patching to protect your organization. #Cybersecurity

    Post summary

    The post announces CVE‑2026‑42370 as a critical unauthenticated stack overflow vulnerability in GeoVision GV‑VMS V20 20.0.2 and urges users to patch affected systems.

    0000050
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42370-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text contains only a link and generic hashtags, providing no concrete information about the CVE beyond its mention.

    0000018
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42370 Stack Overflow Vulnerability in GeoVision GV-VMS V20 20.0.2 WebCam Server Login https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42370

    Post summary

    The snippet lists CVE-2026-42370 as a stack‑overflow vulnerability in GeoVision’s WebCam Server Login but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000048
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-vms20--
OSgeovisiongv-vms_firmware---

Explore more