PT-2026-36737 · Unknown · Gv-Vms V20
Kelly Patterson
+2
·
Published
2026-05-04
·
Updated
2026-06-17
·
CVE-2026-42369
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GV-VMS version V20
Description
A stack overflow exists in the WebCam Server component of the video monitoring software. When remote access is enabled, the
gvapi endpoint utilizes a specific authentication mechanism via an HTTP Authorization header, supporting both Basic and Digest modes. The issue occurs because a base64 decoded string, stored in the b64decoder variable, is copied into the Buffer stack variable without a bound-check. If the decoded string exceeds 256 characters, a stack overflow is triggered. Since the web server is compiled without ASLR (Address Space Layout Randomization), a security technique that randomly arranges the address space positions of key data areas to prevent memory corruption attacks, an attacker can gain full code execution with SYSTEM privileges on the host machine.Recommendations
Update GV-VMS version V20 to a patched version.
Disable the remote access WebCam Server feature to prevent exploitation.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-Vms V20