FAIL › dossier
Multiple Devices
PRODUCT· dossier confidence 25%
GeoVision, a provider of surveillance equipment, has a history of critical security vulnerabilities including remote code execution and password disclosure, raising concerns about the security of their devices. Their products are used in professional security setups, highlighting the need for robust security practices. Ongoing security improvements and proactive vulnerability management are essential.
PROFILE
CategorySurveillance EquipmentWhat they doGeoVision provides video surveillance solutions including IP cameras, NVRs, and access control systems, catering to small to mid-sized businesses. They offer flexible software and remote access capabilities for professional security setups.
Websitehttp://php.gvdip.com/phpbb3/ ↗
SECURITY POSTURE
GeoVision devices have a history of significant security vulnerabilities, including multiple instances of remote code execution and admin password disclosure. Their security posture appears to be a recurring concern, requiring ongoing attention and remediation.
Notable failures
- OS command injection vulnerability (RCE)
- Buffer overflow vulnerability leading to authentication bypass and RCE
- Remote code execution via ping tool
- Admin password disclosure via web requests
- Multiple CVEs related to RCE
Patterns: Recurring OS command injection vulnerabilities; Authentication bypass vulnerabilities; Password disclosure vulnerabilities
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2015-1187 | high | D-Link and TRENDnet devices suffered a remote code execution flaw in their ping tool that was actively exploited in the wild. |
| 2025-05-07 | CVE-2024-6047 | high | GeoVision devices have a critical, actively exploited OS command injection vulnerability allowing remote code execution without authentication, potentially impacting DIB organizations using these devices for surveillance or security purposes. |
| 2025-05-07 | CVE-2024-11120 | high | GeoVision devices have a critical, actively exploited OS command injection vulnerability allowing remote code execution without authentication, potentially impacting DIB organizations using these devices for surveillance or security purposes. |
| 2022-09-08 | CVE-2017-5521 | high | NETGEAR devices exposed admin passwords through crafted requests |
| 2022-06-08 | CVE-2017-6862 | high | Netgear devices had a buffer overflow allowing authentication bypass and remote code execution, actively exploited in the wild. |
DOSSIER SOURCES
- GV FAE Knowledge - Index page · php.gvdip.com
- Are Geovision Ip Cameras Good - surveillanceguides.com · surveillanceguides.com
- An Complete Guide On Enterprise Video Surveillance Ecosystem · www.matrixcomsec.com
Open questions: What is GeoVision's current security development lifecycle? · What remediation steps have been taken to address the identified vulnerabilities? · What is GeoVision's vulnerability disclosure policy?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:25:41.562026+00:00