Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geovision gv-bx1500 Firmware
|
|
| CPEs | cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Geovision gv-bx1500 Firmware
|
Thu, 23 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 21 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geovision
Geovision gv-bx1500 Geovision gv-mfd1501 |
|
| Vendors & Products |
Geovision
Geovision gv-bx1500 Geovision gv-mfd1501 |
Mon, 20 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC. | |
| Title | GeoVision Command Injection RCE via /PictureCatch.cgi | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:03:45.809Z
Reserved: 2025-10-20T17:58:13.659Z
Link: CVE-2018-25118
Updated: 2025-10-21T13:43:49.004Z
Status : Deferred
Published: 2025-10-20T22:15:35.667
Modified: 2026-04-15T00:35:42.020
Link: CVE-2018-25118
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:39:34Z