PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42363 GeoVision Inc. CVE debrief

An insufficient encryption vulnerability in GeoVision GV-IP Device Utility 9.0.5 allows credential theft via passive network monitoring. The utility broadcasts privileged commands over UDP with username and password encrypted using a Blowfish-derived protocol, but the symmetric encryption key is transmitted in the same packet. An attacker on the same LAN can capture broadcast traffic and decrypt credentials using knowledge of the algorithm, gaining full device control including configuration changes and factory reset capability.

Vendor
GeoVision Inc.
Product
GV-IP Device Utility
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-27
Original CVE updated
2026-05-19
Advisory published
2026-04-27
Advisory updated
2026-05-19

Who should care

Organizations using GeoVision IP cameras, access control, or other GV-series devices managed through the GV-IP Device Utility, particularly those with flat network topologies where IoT management traffic shares broadcast domains with user devices.

Technical summary

The GeoVision GV-IP Device Utility 9.0.5 transmits device credentials in UDP broadcast packets using a Blowfish-derived encryption scheme where the symmetric key is included in the same packet. This security-through-obscurity design allows any network observer to decrypt captured traffic and recover plaintext credentials. Successful exploitation grants administrative control over affected GeoVision devices.

Defensive priority

critical

Recommended defensive actions

  • Segment IoT device management traffic to isolated VLANs with no guest or untrusted device access
  • Monitor for UDP broadcast traffic on ports used by GeoVision device discovery and management tools
  • Implement network access control (NAC) to restrict which endpoints can communicate with GeoVision devices
  • Audit and rotate credentials on all GeoVision devices managed by affected utility versions
  • Contact GeoVision for patched utility version and apply security updates when available
  • Consider disabling broadcast-based device discovery in favor of unicast or certificate-based authentication where supported

Evidence notes

Vulnerability disclosed via NVD with CVSS 9.3 (CRITICAL). Source references include Talos Intelligence vulnerability reports and GeoVision security page. NVD status marked as 'Deferred' as of 2026-05-19.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42363 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42363

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42363 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42363

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://talosintelligence.com/vulnerability_reports/

    0df08a0e-a200-4957-9bb0-084f562506f9

  • Source reference

    Unverified legacy reference

    URL: https://www.geovision.com.tw/cyber_security.php

    0df08a0e-a200-4957-9bb0-084f562506f9

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.