CVE-2026-18754
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-AS1620 (GV-Cloud) | V1.16 | affected |
| GeoVision Inc. | GV-AS1620 (GV-Cloud) | V1.17 | unaffected |
Weaknesses
- CWE-321: CWE-321 Use of hard-coded cryptographic key
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.