GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
Published Jun 24, 2026
9.1
CRITICALCVSS 3.1
EPSS 2.70%
Description
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability.
`libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various services, configure IP, Netmask, gateway, dns, etc.)
#### CNetSetObj::m_F_n_Set_IP_Addr command injection
The following function takes a string as an ip address, performs no sanitization and calls `system`. This is a classic command injection vulnerability. The function is reachable from both the network-exposed `DVRSearch` service and the `Network.cgi` endpoint.
int __fastcall CNetSetObj::m_F_n_Set_IP_Addr(const char **this, char *ip_addr)
{
bool v2; // zf
char v4[72]; // [sp+0h] [bp-48h] BYREF
v2 = *this == 0;
if ( *this )
v2 = ip_addr == 0;
if ( v2 )
return 0;
sprintf(v4, "/sbin/ifconfig %s %s", *this, ip_addr); // attacker controlled ip address
system(v4);
return 1;
}
Affected products
-
- Version V2.09StatusaffectedConstraints-
- Version V2.12StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GeoVision Inc. | GV-I/O Box 4E | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38650 Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379 third-party-advisory
- https://www.geovision.com.tw/cyber_security.php vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38650 | Advisory | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379 | third-party-advisory | |
| https://www.geovision.com.tw/cyber_security.php | vendor-advisory |
Change history (0)
No recorded changes yet.