PT-2026-28653 · Unknown · Wvp Gb28181 Pro
Vuldb
+1
·
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-4860
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
648540858 wvp-GB28181-pro versions up to 2.7.4
Description
A security flaw exists in the 648540858 wvp-GB28181-pro software. The issue is related to deserialization within the
GenericFastJsonRedisSerializer function located in the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the API Endpoint component. This allows for remote attacks. The exploit is publicly available. The vendor was notified but did not respond.Recommendations
Versions prior to 2.7.4 should be updated. As a temporary workaround, consider disabling the API Endpoint component until a patch is available.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wvp Gb28181 Pro