CVE-2026-7372General(geovision / gv-vms)

HIGHCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch geovision gv-vms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The call to `sscanf` at [1] to split the `Buffer` variable into the `username` and `password` variables doesn't limit the size of the extracted content to match the destination buffers' sizes. In this case, if either the username or password decoded from the authorization string exceeds `40` characters (the size the stack variables `username` and `password`) then a stack overflow will occur. The data is controlled by an attacker, but sronger constraints (e.g. no null bytes) may make exploitation harder. A successful attack could lead to full code execution as SYSTEM on the machine running the service.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gv-vms
  • gv-vms_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-14); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
gv-vmsgv-vms_firmware

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-04: 2Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-14: 1Exploit Tool / Code · 2026-05-14: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-15: 105-0405-1405-15
Signal classification5 categories
General
233.3%
Active Exploitation
116.7%
Disclosure
116.7%
PoC
116.7%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-042
Active Exploitation1General1
2026-05-143
Disclosure1General1PoC1
2026-05-151
Patch1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7372 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2.

    Post summary

    The text discloses a critical stack overflow vulnerability in GeoVision GV-VMS V20 20.0.2, but does not report any PoC, exploitation, patch, or false‑positive information.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-7372 (CVSS 9) — multiple products. CVE: CVE-2026-7372 CVSS: 9 (3.1) — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text merely lists the CVE-2026-7372 severity and status without additional context such as PoC, exploits, or mitigation details.

    1000034
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical stack overflow vulnerability (CVE-2026-7372) affects GeoVision GV-VMS V20.0.2, allowing unauthenticated attackers to execute code remotely. If you use this system, update or mitigate immediately to protect your network. #Cybersecurity

    Post summary

    This post announces a critical stack overflow vulnerability (CVE-2026-7372) in GeoVision GV-VMS V20.0.2 that permits remote code execution and urges users to promptly apply updates or mitigations.

    0000052
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    https://lyrie.ai/research/research/cve-2026-7372-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory announces CVE‑2026‑7372 as a zero‑day vulnerability, provides a PoC/exploit and technical details, but does not report active exploitation or a patch.

    0000019
    210 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    GeoVision GV-VMS V20 WebCam Server Login CVE-2026-7372 is being exploited now—attackers can execute arbitrary code remotely via stack overflow. Patch immediately to mitigate this critical vulnerability. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #WordPress https://t.co/JljD4FZtu0

    Post summary

    The message reports that CVE-2026-7372 is currently being exploited for remote code execution through a stack overflow, and urges immediately applying patches.

    0000052
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7372 Stack Overflow in GeoVision GV-VMS V20 20.0.2 WebCam Serve... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7372 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026-7372 and provides a link to vulnerability details, but offers no technical specifics, PoC, or exploit information.

    0000053
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWgeovisiongv-vms20--
OSgeovisiongv-vms_firmware---

Explore more