:::

[Security Vulnerability Alert] GeoVision has a security vulnerability (CVE-2018-25118). Please confirm and patch it as soon as possible.

Type:行政公告
Pubish Date:2025/10/30 至 2026/04/30
Visitors:347

Forwarded from the National Cybersecurity Information Sharing and Analysis Center (NISAC-200-202510-00000262)

[Content Description] Researchers have discovered an OS Command Injection vulnerability (CVE-2018-25118) in GeoVision embedded IP devices. An unauthenticated remote attacker could inject arbitrary operating system commands and execute them on the device. This vulnerability has already been exploited by hackers; please confirm and patch it as soon as possible.

[Affected Platforms] GV-BX1500, GV-MFD1501, and other embedded IP devices with firmware release dates prior to December 2017.

[Recommended Actions] Please update your firmware to the latest version.

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2018-25118
2. https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi

相關附件

※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。

返回列表