GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. |
21 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15 - | |
| References | () https://www.exploit-db.com/exploits/43982 - | |
| References | () https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi - |
20 Oct 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-20 22:15
Updated : 2025-10-23 14:15
NVD link : CVE-2018-25118
Mitre link : CVE-2018-25118
CVE.ORG link : CVE-2018-25118
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
