PT-2026-36737 · Unknown · Gv-Vms V20

Kelly Patterson

+2

·

Published

2026-05-04

·

Updated

2026-06-17

·

CVE-2026-42369

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GV-VMS version V20
Description A stack overflow exists in the WebCam Server component of the video monitoring software. When remote access is enabled, the gvapi endpoint utilizes a specific authentication mechanism via an HTTP Authorization header, supporting both Basic and Digest modes. The issue occurs because a base64 decoded string, stored in the b64decoder variable, is copied into the Buffer stack variable without a bound-check. If the decoded string exceeds 256 characters, a stack overflow is triggered. Since the web server is compiled without ASLR (Address Space Layout Randomization), a security technique that randomly arranges the address space positions of key data areas to prevent memory corruption attacks, an attacker can gain full code execution with SYSTEM privileges on the host machine.
Recommendations Update GV-VMS version V20 to a patched version. Disable the remote access WebCam Server feature to prevent exploitation.

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42369

Affected Products

Gv-Vms V20