← Back to browse · API

CVE-2018-25118

Severity
CRITICAL
CVSS
10.0
EPSS
0.013
Risk score
40.45
CISA KEV
No
PoC
No
Published
2025-10-20
Modified
2026-04-07
First seen
2026-08-07
Aliases
EUVD-2018-21605, GHSA-JW2V-JC28-RFH8
Products
GeoVision Inc.:GV-BX1500 0 <November/December 2017 firmware, GeoVision Inc.:GV-MFD1501 0 <November/December 2017 firmware, GeoVision Inc.:GeoVision embedded IP devices 0 <November/December 2017 firmware
Sources
euvd EUVD-2018-21605

Description

GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

References