Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
V6.2.0
affected
V6.3.0
unaffected
Description
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.
Problem types
CWE-94: Improper Control of Generation of Code ('Code Injection')
Product status
V6.2.0
V6.3.0
Timeline
| 2026-04-28: | Initial report to vendor |
Credits
Patrick Tung
References
www.geovision.com.tw/cyber_security.php