{"cve":"CVE-2018-25118","enrichment":{"created":"2025-10-21T09:39:34.208067+00:00","updated":"2025-10-21T09:39:34.208101+00:00","vendors":["geovision","geovision$PRODUCT$gv-bx1500","geovision$PRODUCT$gv-mfd1501"]},"epss":{"score":0.01267},"mitre":{"cpes":["cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*"],"created":"2025-10-20T21:14:41.304000+00:00","description":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2018/25xxx/CVE-2018-25118.json","references":["https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15","https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a","https://www.exploit-db.com/exploits/43982","https://www.geovision.com.tw/blog/?cat=14","https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi"],"title":"GeoVision Command Injection RCE via /PictureCatch.cgi","updated":"2026-04-07T14:03:45.809000+00:00","vendors":["geovision","geovision$PRODUCT$gv-bx1500_firmware"],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2025-10-20T22:15:35.667000+00:00","description":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10.0,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2018/CVE-2018-25118.json","references":["https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15","https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a","https://www.exploit-db.com/exploits/43982","https://www.geovision.com.tw/blog/?cat=14","https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi"],"title":null,"updated":"2026-06-17T01:54:45.520000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-10-20T21:30:00+00:00","data":[{"details":{"new":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","old":null},"type":"description"},{"details":{"new":"GeoVision Command Injection RCE via /PictureCatch.cgi","old":null},"type":"title"},{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15","https://www.exploit-db.com/exploits/43982","https://www.geovision.com.tw/blog/?cat=14","https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"94cb7ab9-9b3a-4eaa-bfef-36752f268247"},{"created":"2025-10-21T09:45:00+00:00","data":[{"details":["geovision","geovision$PRODUCT$gv-bx1500","geovision$PRODUCT$gv-mfd1501"],"type":"first_time"},{"details":{"added":["geovision","geovision$PRODUCT$gv-bx1500","geovision$PRODUCT$gv-mfd1501"],"removed":[]},"type":"vendors"}],"id":"842ca346-ade9-41bd-b2a4-ac18faad943a"},{"created":"2025-10-21T15:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"5f9e82a9-676f-4ef9-999e-0bce0c9e386e"},{"created":"2025-10-21T15:45:00+00:00","data":[{"details":{"added":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a"],"removed":[]},"type":"references"}],"id":"f985be91-6a9e-4864-bf9c-a700e2fba424"},{"created":"2025-10-23T13:30:00+00:00","data":[{"details":{"new":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","old":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC."},"type":"description"},{"details":{"added":{},"removed":{},"updated":{"cvssV4_0":{"new":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"old":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}}}},"type":"metrics"}],"id":"43474e41-beb4-4c91-ad5f-f024730da317"},{"created":"2025-11-21T14:45:00+00:00","data":[{"details":["geovision$PRODUCT$gv-bx1500_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["geovision$PRODUCT$gv-bx1500_firmware"],"removed":[]},"type":"vendors"}],"id":"1e069e37-59cf-4336-8d86-d51ed91a6993"}],"cpes":{"data":["cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2025-10-20T21:14:41.304000+00:00","provider":"mitre"},"description":{"data":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.01267},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15","https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a","https://www.exploit-db.com/exploits/43982","https://www.geovision.com.tw/blog/?cat=14","https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":"GeoVision Command Injection RCE via /PictureCatch.cgi","provider":"mitre"},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":["geovision","geovision$PRODUCT$gv-bx1500","geovision$PRODUCT$gv-bx1500_firmware","geovision$PRODUCT$gv-mfd1501"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-10-20T21:14:41.304000+00:00","description":"GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://github.com/mcw0/PoC/blob/fb06efe05b7e240dc88ff31eb30e1ef345509dce/Geovision-PoC.py#L15","https://www.exploit-db.com/exploits/43982","https://www.vulncheck.com/advisories/geovision-command-injection-rce-picture-catch-cgi"],"title":"GeoVision Command Injection RCE via /PictureCatch.cgi","updated":"2025-10-21T13:43:49.004000+00:00","vendors":[],"vulnrichment_repo_path":"2018/25xxx/CVE-2018-25118.json","weaknesses":[]}}