Cisco Talos disclosed newly patched vulnerabilities in GeoVision products as part of a broader third-party advisory covering WolfSSL, GeoVision, and VTK-DICOM. The GeoVision portion spans 14 advisories and 37 CVEs, including weaknesses such as OS command injection, privilege escalation, reflected XSS, guessable session cookies, insufficient encryption, lack of authentication, and buffer-handling flaws. Talos said the affected vendors have released patches and noted that Snort coverage is available to help detect exploitation attempts.
Reporting on the GeoVision issues highlighted critical flaws in LPC2011/LPC2211 license-plate recognition cameras and GV-VMS software. In particular, CVE-2026-42364 is an OS command injection in DdnsSetting.cgi on camera firmware 1.10, and CVE-2026-42368 is a privilege-escalation bug that can be chained for full root compromise through the web interface; a separate flaw, CVE-2026-42369, enables unauthenticated remote code execution in GV-VMS V20. Because the cameras are commonly deployed in parking, checkpoint, hospital, airport, and other physical-security environments, successful exploitation could provide a foothold for lateral movement, surveillance disruption, and access into adjacent building-management or access-control networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos disclosed multiple newly patched third-party vulnerabilities affecting WolfSSL, GeoVision products, and VTK-DICOM under its third-party disclosure policy. The disclosure covered three WolfSSL flaws, fourteen GeoVision advisories spanning 37 CVEs, and one VTK-DICOM vulnerability, and noted that Snort coverage is available to help detect exploitation.
A cluster of seven vulnerabilities affecting GeoVision LPC2011/LPC2211 license-plate recognition cameras and GeoVision GV-VMS software was disclosed. The disclosure included critical issues such as OS command injection (CVE-2026-42364), privilege escalation (CVE-2026-42368), and an unauthenticated RCE in GV-VMS (CVE-2026-42369).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.