HarborGuard / CVE
Back to search
HIGHCVE-2026-7841Published Modified CNA GV

CVE-2026-7841: GV-ASWeb Remote Code Execution (RCE) vulnerability

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
V6.3.0
Affected Products
1

Fix available

V6.3.0
Affected packages
  • GeoVision Inc. / ASManager
    V6.2.0
    Fixed in V6.3.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-7841: GV-ASWeb Remote Code Execution (RCE) vulnerability | HarborGuard CVE