A remote code execution vulnerability
exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated
user with System Setting permissions can execute arbitrary commands on the
server by sending a crafted HTTP POST request to the ASWebCommon.srf backend
endpoint to bypass the frontend restrictions.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
|
History
Wed, 06 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geovision
Geovision gv-asmanager |
|
| Vendors & Products |
Geovision
Geovision gv-asmanager |
Wed, 06 May 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions. | |
| Title | GV-ASWeb Remote Code Execution (RCE) vulnerability | |
| First Time appeared |
Geovision Inc.
Geovision Inc. asmanager |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:geovision_inc.:asmanager:v6.2.0:*:windows:*:*:*:*:* cpe:2.3:a:geovision_inc.:asmanager:v6.3.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. asmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GV
Published: 2026-05-06T06:47:53.765Z
Updated: 2026-05-07T01:13:11.587Z
Reserved: 2026-05-05T07:36:15.083Z
Link: CVE-2026-7841
Updated: 2026-05-06T12:54:45.679Z
Status : Received
Published: 2026-05-06T08:16:04.490
Modified: 2026-05-06T08:16:04.490
Link: CVE-2026-7841
No data.
ReportizFlow