CVE-2026-7161 Details
Description
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcasted over UDP and the username/password are encrypted using a cryptographic protocol that appears to be derivated from Blowfish. However the symmetric key used for the encryption is also included in the packet, and thus the security of the username/password only relies on the "obscurity" of the encryption scheme. An attacker on the same LAN can listen to the broadcast traffic once an admin user interacts with the device, and decrypt the credentials using their own implementation of the algorithm. With this password the attacker would have full control over the device configuration, allowing them to change its ip address or even reset it to factory default.
A vulnerability allowing credential leakage through insufficient encryption has been identified in the Device Authentication feature of GeoVision GV-IP Device Utility version 9.0.5. This issue arises when the utility interacts with various GeoVision devices over the network, as it may send privileged commands that require the device's username and password. While the credentials are encrypted using a cryptographic protocol resembling Blowfish, the symmetric key for the encryption is also included in the broadcasted UDP packets. This design flaw allows an attacker on the same local area network to intercept and decrypt the credentials, gaining full control over the device's configuration, including the ability to change its IP address or reset it to factory defaults.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://talosintelligence.com/vulnerability_reports/ | GV | Third Party Advisory |
| https://www.geovision.com.tw/cyber_security.php | GV | Vendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2322 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-656 | Reliance on Security Through Obscurity | GV |
Affected Products
| Product | Versions |
|---|---|
| geovision gv-ip device utility | 9.0.5 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | GV |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CVE |
| May 5, 2026 | Initial Analysis | [email protected] |
| May 4, 2026 | New CVE Received | GV |