GeoVision GV-IP Device Utility Insufficient Encryption Vulnerability in Device Authentication

Vulnerability

A vulnerability allowing credential leakage through insufficient encryption has been identified in the Device Authentication feature of GeoVision GV-IP Device Utility version 9.0.5. When an admin user interacts with certain GeoVision devices over the network, the utility may send privileged commands that require the device's username and password. Although the credentials are encrypted using a cryptographic protocol resembling Blowfish, the symmetric key for the encryption is included in the same packet. This design flaw allows an attacker on the same local area network to intercept and decrypt the credentials, gaining full control over the device's configuration, including the ability to change its IP address or reset it to factory defaults.

Impact

Exploitation of this vulnerability allows an attacker to intercept and decrypt broadcasted credentials, giving them full control over the affected GeoVision device's configuration.

Added: Apr 27, 2026, 12:23 AM
Updated: Apr 27, 2026, 12:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
6.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.