CVE Feed

    Dashboard / CVE / CVE-2018-25118

    CVE-2018-25118

    GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

    Published:Oct 20, 2025
    Last Modified:Apr 15, 2026
    EPS:Oct 20, 2025
    EPSS Score:0.00584
    CVSS Score:10

    Affected Products

    Vendor
    Geovision
    Product
    Gv-bx1500
    Vendor
    Geovision
    Product
    Gv-bx1500 Firmware
    Vendor
    Geovision
    Product
    Gv-mfd1501

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High