Description
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
Published: 2026-08-04
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware contains an embedded, static RSA private key that Lighttpd uses for TLS termination. Exposure of that key allows an attacker to decrypt HTTPS communications and spoof the server, undermining the confidentiality and integrity of encrypted traffic. The flaw represents a classic cryptographic key exposure (CWE-321).

Affected Systems

The affected product is the GeoVision Inc. GV‑AS1620 controller firmware (AS‑Manager). No specific firmware revisions are listed in the report.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves remote exploitation of the lighttpd web server through the embedded private key, allowing an adversary to intercept or modify traffic to and from the device.

Generated by OpenCVE AI on August 4, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that removes the hard‑coded RSA private key or replaces it with a secure, configurable key
  • If an update is unavailable, disable the device’s web server or restrict its access to trusted networks until a fix can be applied
  • Continuously monitor traffic for abnormal TLS behavior and enforce TLS pinning if supported by the device

Generated by OpenCVE AI on August 4, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Geovision
Geovision gv-asmanager
Vendors & Products Geovision
Geovision gv-asmanager

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Title Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager)
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Geovision Gv-asmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-08-04T13:36:24.896Z

Reserved: 2026-08-04T00:55:05.974Z

Link: CVE-2026-18753

cve-icon Vulnrichment

Updated: 2026-08-04T13:35:17.937Z

cve-icon NVD

Status : Received

Published: 2026-08-04T08:16:34.640

Modified: 2026-08-04T14:16:31.280

Link: CVE-2026-18753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:45:06Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key