Impact
The firmware for GeoVision's GV‑AS1620 controller embeds a static RSA private key used by Lighttpd for TLS termination, a textbook example of CWE‑321: Hard‑Coded Cryptographic Key. When the key becomes exposed, an attacker can decrypt HTTPS traffic and spoof the controller, thereby breaching confidentiality and integrity of communications.
Affected Systems
This vulnerability affects GeoVision Inc.'s GV‑AS1620 controller running the GV‑Cloud firmware. No specific firmware version range is stated, so all releases that include the embedded key are potentially impacted.
Risk and Exploitability
With a CVSS score of 9.1 the vulnerability is considered critical. No EPSS score is available and it is not listed in the CISA KEV catalog. The likely attack vector is exposure of the firmware or unauthorized access to the device, after which the static key can be extracted and used to decrypt live TLS sessions or impersonate the controller. Successful exploitation would allow traffic eavesdropping and denial of service through spoofing.
OpenCVE Enrichment