Skip to content
COOEY

FAIL › dossier

Multiple Devices

PRODUCT

· dossier confidence 25%

GeoVision, a provider of surveillance equipment, has a history of critical security vulnerabilities including remote code execution and password disclosure, raising concerns about the security of their devices. Their products are used in professional security setups, highlighting the need for robust security practices. Ongoing security improvements and proactive vulnerability management are essential.

PROFILE
CategorySurveillance EquipmentWhat they doGeoVision provides video surveillance solutions including IP cameras, NVRs, and access control systems, catering to small to mid-sized businesses. They offer flexible software and remote access capabilities for professional security setups. Websitehttp://php.gvdip.com/phpbb3/ ↗
SECURITY POSTURE

GeoVision devices have a history of significant security vulnerabilities, including multiple instances of remote code execution and admin password disclosure. Their security posture appears to be a recurring concern, requiring ongoing attention and remediation.

Notable failures
  • OS command injection vulnerability (RCE)
  • Buffer overflow vulnerability leading to authentication bypass and RCE
  • Remote code execution via ping tool
  • Admin password disclosure via web requests
  • Multiple CVEs related to RCE
Patterns: Recurring OS command injection vulnerabilities; Authentication bypass vulnerabilities; Password disclosure vulnerabilities
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2015-1187 high D-Link and TRENDnet devices suffered a remote code execution flaw in their ping tool that was actively exploited in the wild.
2025-05-07 CVE-2024-6047 high GeoVision devices have a critical, actively exploited OS command injection vulnerability allowing remote code execution without authentication, potentially impacting DIB organizations using these devices for surveillance or security purposes.
2025-05-07 CVE-2024-11120 high GeoVision devices have a critical, actively exploited OS command injection vulnerability allowing remote code execution without authentication, potentially impacting DIB organizations using these devices for surveillance or security purposes.
2022-09-08 CVE-2017-5521 high NETGEAR devices exposed admin passwords through crafted requests
2022-06-08 CVE-2017-6862 high Netgear devices had a buffer overflow allowing authentication bypass and remote code execution, actively exploited in the wild.
Open questions: What is GeoVision's current security development lifecycle? · What remediation steps have been taken to address the identified vulnerabilities? · What is GeoVision's vulnerability disclosure policy?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:25:41.562026+00:00