CVE-2026-18754

GeoVision · GV-AS1620 (GV-Cloud)

The GeoVision GV-AS1620 GV-Cloud firmware contains a hard-coded RSA private key, which allows attackers to decrypt HTTPS traffic and spoof the server.

Executive summary

A critical security flaw in GeoVision GV-AS1620 GV-Cloud firmware exposes a static RSA private key, facilitating traffic decryption and server impersonation.

Vulnerability

The firmware utilizes an embedded, static RSA private key for Lighttpd web server TLS termination (CWE-321). This allows unauthenticated attackers to intercept and decrypt encrypted communications or perform man-in-the-middle attacks to spoof the server.

Business impact

With a CVSS score of 9.1, this vulnerability poses a severe threat to the confidentiality and integrity of management communications. Compromise of the private key enables attackers to capture sensitive credentials or configuration data in transit, effectively neutralizing the protection offered by HTTPS.

Remediation

Immediate Action: Update the GeoVision GV-AS1620 (GV-Cloud) firmware to version V1.17 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual TLS handshake patterns or unauthorized certificate usage that might indicate an active man-in-the-middle attempt.

Compensating Controls: Isolate the management interface of the GV-AS1620 to a restricted management VLAN, ensuring that it is not exposed to the public internet.

Exploitation status

Public Exploit Available: False

Analyst recommendation

The reliance on a static, hard-coded key renders the current firmware version insecure. Administrators must upgrade to version V1.17 immediately to rotate the keys and restore the confidentiality of administrative sessions.