GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1)
cve · CVE-2026-12486 single-source
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Talos discloses 41 patched CVEs: wolfSSL silently ignores IP/registeredID cert name constraints, GeoVision…
Peak priority
notable
1 notable
Targets
healthcare
sectors: healthcare, public-sector, technology
Sources cited
7
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-12486, newest first. Check the date before acting on an older one.
- If you rely on wolfSSL-based TLS validation with constrained sub-CAs, do not assume the client enforces name constraints: patch wolfSSL and review any trust model that depends on iPAddress or registeredID SAN name-constraint enforcement, which wolfSSL silently skipped.2026-07-09CVE-2026-7532 +5
- Inventory GeoVision physical-security hardware (GV-I/O boxes, DVR/NVR, GV-VMS/GV-Cloud, GeoWebPlayer) in facilities; confirm firmware is on the vendor-patched builds and that management interfaces (DVRSearch discovery, Network.cgi) are off any network reachable by untrusted hosts.2026-07-09CVE-2026-7532 +5
- For healthcare imaging pipelines that ingest external DICOM files via VTK-DICOM, patch to the fixed release and hunt for DICOM-parsing processes crashing/aborting on ingest as a sign of malformed-file submission.2026-07-09CVE-2026-7532 +5
Defender insights
What each entry about CVE-2026-12486 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessDrive-by Compromise · Exploit Public-Facing Application
- ExecutionExploitation for Client Execution
- Defense ImpairmentSubvert Trust Controls
Initial Access TA0001
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure · ATT&CK page ↗
Execution TA0002
T1203Exploitation for Client Execution×1
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Evidence: 2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure · ATT&CK page ↗
Defense Impairment TA0112
T1553Subvert Trust Controls×1
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.
Evidence: 2026-07-09/talos-wolfssl-geovision-vtkdicom-disclosure · ATT&CK page ↗
Entries about GeoVision GV-I/O Box 4E unauthenticated OS command injection (Talos, CVSS 9.1) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- GeoVision GeoWebPlayer×1
- GeoVision GeoWebPlayer unauthenticated localhost WebSocket screen-capture (Talos, CVSS 8.8)×1
- GeoVision GV-I/O Box 4E×1
- vtk-dicom×1
- VTK-DICOM heap overflow on crafted DICOM file (Talos, CVSS 8.1)×1
- wolfSSL×1
- wolfSSL iPAddress SAN name-constraint bypass (Talos coordinated disclosure, CVSS 9.1)×1
- wolfSSL PKCS#7 OtherRecipientInfo integer underflow -> heap overflow (Talos, CVSS 7.5)×1
Where this entity is cited
Source distribution
- talosintelligence.com6 (86%)
- blog.talosintelligence.com1 (14%)
External references
All cited sources (7)
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2366)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2366
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2370)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2370
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2379)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2379
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2408)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2408
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2409)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2409
- talosintelligence.comprimaryCisco Talos (TALOS-2026-2410)https://talosintelligence.com/vulnerability_reports/TALOS-2026-2410
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/wolfssl-vulnerabilities/