CVE-2018-25118
GeoVision Command Injection RCE via /PictureCatch.cgi
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
GeoVision Inc. · GeoVision embedded IP devicesGeoVision Inc. · GV-BX1500GeoVision Inc. · GV-MFD1501public PoCs found — 3
cve_referencegithub.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15unverifiedcve_referencewww.cisa.gov/news-events/cybersecurity-advisories/aa24-249aunverifiedcve_referencewww.exploit-db.com/exploits/43982unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249ahttps://www.exploit-db.com/exploits/43982https://www.geovision.com.tw/blog/?cat=14https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi