CVE-2025-26264

GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
Configurations

No configuration.

History

19 Mar 2025, 14:15

Type Values Removed Values Added
Summary (en) GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise. (en) GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.

17 Mar 2025, 06:15

Type Values Removed Values Added
References
  • () https://www.geovision.com.tw/download/product/GV-ASManager%20%28Access%20Control%29 -

28 Feb 2025, 22:15

Type Values Removed Values Added
References () https://github.com/DRAGOWN/CVE-2025-26264 - () https://github.com/DRAGOWN/CVE-2025-26264 -

28 Feb 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-94
Summary
  • (es) GeoVision GV-ASWeb con la versión 6.1.2.0 o anterior contiene una vulnerabilidad de ejecución remota de código (RCE) en su función de configuración de notificaciones. Un atacante autenticado con privilegios de "Configuración del sistema" en ASWeb puede aprovechar esta falla para ejecutar comandos arbitrarios en el servidor, lo que provocaría un compromiso total del sistema.

27 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 22:15

Updated : 2025-03-19 14:15


NVD link : CVE-2025-26264

Mitre link : CVE-2025-26264

CVE.ORG link : CVE-2025-26264


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')