🔐 CVE Alert

CVE-2026-12488

MEDIUM 6.2

GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability.

CWE CWE-121
Vendor geovision inc.
Product geovision
Published Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for geovision inc. geovision

Be the first to know when new medium vulnerabilities affecting geovision inc. geovision are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
High

Affected Versions

GeoVision Inc. / GeoVision
V20.0.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
geovision.com.tw: https://www.geovision.com.tw/cyber_security.php talosintelligence.com: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2411 talosintelligence.com: https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2411

Credits

Philippe Laulheret of Cisco Talos. Kelly Patterson of Cisco Talos. Robert Sherwin of Cisco Talos.