PT-2026-27208 · Genersoft · Wvp Gb28181 Pro
Vuldb
+1
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2026-4597
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
648540858 wvp-GB28181-pro versions up to 2.7.4
Description
A security flaw exists in the Stream Proxy Query Handler component of 648540858 wvp-GB28181-pro. Specifically, the
selectAll function within the file src/main/java/com/genersoft/iot/vmp/streamProxy/dao/provider/StreamProxyProvider.java is susceptible to SQL injection. This manipulation can be initiated remotely. The exploit for this issue has been publicly released.Recommendations
Versions prior to 2.7.4 should be updated.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wvp Gb28181 Pro