CVE-2026-42363 — An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the c CVSSv3.1 9.3 (CRITICAL)