CVE-2026-7841
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
06/05/2026
Last modified:
07/05/2026
Description
A remote code execution vulnerability<br />
exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated<br />
user with System Setting permissions can execute arbitrary commands on the<br />
server by sending a crafted HTTP POST request to the ASWebCommon.srf backend<br />
endpoint to bypass the frontend restrictions.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH



