#gvapi
CRITICAL: GeoVision GV-VMS V20.0.2 stack overflow (CVSS 10) lets remote attackers gain SYSTEM access. Restrict remote access & monitor for patches. https://radar.offseq.com/threat/cve-2026-42369-cwe-787-out-of-bounds-write-in-geov-0757b787 #OffSeq #CVE202642369 #cyberalert
CVE-2026-42369: CWE-787 Out-of-bounds write in GeoVision Inc. GV-VMS V20.0.2
GV-VMS V20.0.2 includes a native webserver component that handles remote access and authentication. The gvapi endpoint processes an HTTP Authorization header that is base64 decoded into a dynamically sized string. This decoded string is the
radar.offseq.com
May 4, 2026 at 6:00 AM
March 7, 2026 at 2:11 AM
🔎 Technical breakdown:
• CWE-787 (Buffer Overflow)
• Stack overflow in gvapi auth handling
• No ASLR → easier exploitation
• Unauthenticated RCE as SYSTEM

Impact: Full takeover of surveillance systems
#InfoSec #Vulnerability
May 4, 2026 at 8:41 AM