CVE-2026-7841

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/05/2026
Last modified:
07/05/2026

Description

A remote code execution vulnerability<br /> exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated<br /> user with System Setting permissions can execute arbitrary commands on the<br /> server by sending a crafted HTTP POST request to the ASWebCommon.srf backend<br /> endpoint to bypass the frontend restrictions.

References to Advisories, Solutions, and Tools