CVE-2018-25118

GeoVision Command Injection RCE via /PictureCatch.cgi

Basic Information

CVE State
PUBLISHED
Reserved Date
October 20, 2025
Published Date
October 20, 2025
Last Updated
April 07, 2026
Vendor
GeoVision Inc.
Product
GV-BX1500, GV-MFD1501, GeoVision embedded IP devices
Description
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

CVSS Scores

CVSS v4.0

10.0 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC Information

Exploitation
poc
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:42:30 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:42:30 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel