CVE-2025-26264

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 27, 2025
Updated: Feb 28, 2025
CWE ID 94

Summary

CVE-2025-26264 is a Remote Code Execution (RCE) vulnerability affecting the Notification Settings feature in GeoVision GV-ASWeb version 6.1.2.0 and below. Authenticated attackers with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, resulting in a full system compromise. This vulnerability poses a significant risk to organizations using the affected version of GeoVision GV-ASWeb and highlights the importance of keeping software up-to-date with the latest security patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share