CVE-2026-7161Disclosure(geovision / gv-ip_device_utility)

HIGHCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch geovision gv-ip_device_utility systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-656

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-ip_device_utility

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-14); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
gv-ip_device_utility

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-04: 1Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-05-14: 1Exploit Tool / Code · 2026-05-14: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-15: 105-0405-1405-1510-07
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-142
Exploit1General1
2026-05-151
Disclosure1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7161 CVSS: 9.3 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text lists CVE‑2026‑7161 as a critical vulnerability with a CVSS of 9.3 but provides no proof‑of‑concept, exploitation details, or mitigation information.

    1000038
    210 followersView on X
  • CISO Marketplace@CisoMarketplace

    GeoVision camera credentials can be decrypted from a single UDP broadcast packet — no password theft needed. CVSS 9.3, CVE-2026-42363 & CVE-2026-7161, per SentinelOne. Patch guide for estate security teams: https://secureiot.house/geovision-udp-credential-leak-full-mitigation-guide-estate-camera-systems/ #IoTSecurity #CVE https://t.co/kju1TerCas

    0000052
    375 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A high-severity flaw (CVE-2026-7161) in GeoVision GV-IP Device Utility 9.0.5 can expose device credentials over the network, risking unauthorized control. SMBs using these devices should monitor updates and limit network exposure to reduce risk. #Cybersecurity

    Post summary

    The post reports a high‑severity flaw (CVE‑2026‑7161) that can expose device credentials over the network, with advisories to monitor updates and limit exposure, but offers no exploit, PoC, or evidence of active exploitation.

    0000050
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    https://lyrie.ai/research/research/cve-2026-7161-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory provides a PoC, functional exploit code, notes active exploitation in the wild, offers a patch, and includes technical vulnerability details, indicating a high‑confidence exploit alert.

    0000016
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7161 Insufficient Encryption in GeoVision GV-IP Device Utility 9.0.5 Credential Leak https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7161

    Post summary

    CVE-2026-7161 is disclosed as a credential leakage vulnerability due to insufficient encryption in GeoVision GV-IP Device Utility 9.0.5, with no evidence of exploitation, patch, or PoC provided.

    0000063
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgeovisiongv-ip_device_utility9.0.5--

Explore more