CVE-2018-25118

GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Oct 2025, 14:15

Type Values Removed Values Added
Summary (en) GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. (en) GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

21 Oct 2025, 16:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a -

21 Oct 2025, 14:15

Type Values Removed Values Added
References () https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15 - () https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15 -
References () https://www.exploit-db.com/exploits/43982 - () https://www.exploit-db.com/exploits/43982 -
References () https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi - () https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi -

20 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-20 22:15

Updated : 2025-10-23 14:15


NVD link : CVE-2018-25118

Mitre link : CVE-2018-25118

CVE.ORG link : CVE-2018-25118


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')