CVE-2025-26264
46Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 21%
from disclosure to weapon0 days
Published on NVDFeb 27
1st PoCFeb 26
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52424unverifiedgithubgithub.com/DRAGOWN/CVE-2025-26264★ 7⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.