Impact
The firmware contains an embedded, static RSA private key that Lighttpd uses for TLS termination. Exposure of that key allows an attacker to decrypt HTTPS communications and spoof the server, undermining the confidentiality and integrity of encrypted traffic. The flaw represents a classic cryptographic key exposure (CWE-321).
Affected Systems
The affected product is the GeoVision Inc. GV‑AS1620 controller firmware (AS‑Manager). No specific firmware revisions are listed in the report.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves remote exploitation of the lighttpd web server through the embedded private key, allowing an adversary to intercept or modify traffic to and from the device.
OpenCVE Enrichment