Impact
GV‑Eye, a proprietary Android application developed by GeoVision Inc., contains a fixed API key that is embedded directly in the application bundle. This key can be extracted by anyone with the APK through reverse engineering techniques, exposing it for misuse by unauthorized users. The exposed key can be used to call GV‑Eye’s backend services, potentially allowing attackers to access or manipulate data and resources that should be protected, thereby compromising confidentiality and integrity. The weakness corresponds to CWE‑312, CWE‑540, and CWE‑798, all of which indicate insecure storage and use of credentials.
Affected Systems
GeoVision Inc. GV‑Eye version 3.6.0 and 3.7.2 for Android. The vulnerability exists in applications distributed for the Android platform.
Risk and Exploitability
Because the key is embedded, an attacker only needs to obtain the APK, which is readily available to anyone who installs the app. Reverse engineering is safe and allowed, removes the need for network interaction or special privileges, making exploitation straightforward. The CVSS score of 7.5 classifies it as a high severity vulnerability, and while an EPSS score is not provided, the ease of extraction suggests a non‑negligible probability of exploitation. The vulnerability is currently not listed in the CISA KEV catalog, but the exposure could be considerable for users relying on the API functionality.
OpenCVE Enrichment