Description
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.

The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.



#### 2wayAudio command index-out-of-bound
Published: 2026-07-02
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GeoVision GeoWebPlayer exposes a websocket server that accepts commands originating from local hosts. Several commands include an integer "index" parameter that is used to index internal arrays without bounds checking. This omission creates an out‑of‑bounds read condition (CWE‑129). A crafted command that abuses this flaw could read memory beyond the intended array boundaries, potentially exposing sensitive data stored adjacent to the accessed region. Based on the description, it is inferred that an attacker could read memory beyond the intended array boundaries and potentially expose sensitive data stored adjacent to the accessed region, such as confidential configuration or operational information.

Affected Systems

Affected are GeoVision Inc. GeoWebPlayer versions earlier than 1.1.3.0, notably the 1.1.1.0 releases for both 64‑bit and Windows platforms. The vendor has released GeoWebPlayer V1.1.3.0 that contains the fix. Upgrading to this patched version removes the vulnerability.

Risk and Exploitability

The CVSS score of 8.3 indicates a high‑severity weakness. The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require local or locally trusted network access to the websocket interface to send malformed commands that trigger the out‑of‑bounds reads. No arbitrary code execution, privilege escalation, or denial of service is implied or supported by the description.

Generated by OpenCVE AI on July 22, 2026 at 13:57 UTC.

Remediation

Vendor Solution

The vulnerability has been patched with GeoWebPlayer V1.1.3.0


OpenCVE Recommended Actions

  • Apply GeoWebPlayer V1.1.3.0 patch.
  • If upgrading is not immediately possible, temporarily disable the websocket server until the patch is applied.
  • Restrict the websocket interface so that only trusted local processes or hosts can connect.

Generated by OpenCVE AI on July 22, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound. #### 2wayAudio command index-out-of-bound
Title GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
First Time appeared Geovision Inc.
Geovision Inc. geowebplayer
Weaknesses CWE-129
CPEs cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:windows:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:windows:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. geowebplayer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Geowebplayer
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-07-02T12:36:07.280Z

Reserved: 2026-06-24T05:48:03.740Z

Link: CVE-2026-57266

cve-icon Vulnrichment

Updated: 2026-07-02T12:36:01.566Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index