


Perceptive Security
SOC/SIEM Consultancy

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packe…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 01:02:15
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
An insufficient encryption vulnerability exists in GeoVision GV-IP Device Utility 9.0.5 that allows credential theft through broadcast packet interception. The vulnerability occurs in the Device Authentication functionality where privileged commands are sent over UDP with encrypted username/password pairs using a Blowfish-derived protocol. However, the symmetric encryption key is included in the same packet, making the encryption rely solely on obscurity. Attackers on the same LAN can intercept broadcast traffic when administrators interact with devices and decrypt the credentials using their own algorithm implementation. With these stolen credentials, attackers gain full control over device configuration, including the ability to change IP addresses or reset devices to factory defaults.
Technical details
Mitigation steps:
Affected products:
GeoVision GV-IP Device Utility 9.0.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42363
https://talosintelligence.com/vulnerability_reports/
https://www.geovision.com.tw/cyber_security.php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
