CVE-2025-26264

GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
Configurations

No configuration.

History

No history.

Information

Published : 2025-02-27 22:15

Updated : 2025-03-19 14:15


NVD link : CVE-2025-26264

Mitre link : CVE-2025-26264

CVE.ORG link : CVE-2025-26264


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')