← Back to Research Blog
CRITICAL CVE-2026-12848

Critical Remote Code Execution in GV-I/O Box 4E DVRSearch Service (CVE-2026-12848)

10.0
CRITICAL
dvrsearch, gv-i-o box 4e
2026-08-12

Overview

A stack overflow vulnerability in the default DVRSearch service of GV-I/O Box 4E enables unauthenticated attackers to execute arbitrary code remotely via crafted UDP packets. This CVSS 10.0 flaw requires immediate mitigation for industrial and enterprise environments.


Technical Analysis

The vulnerability arises from unchecked copying of a user-controlled DNS address string into a fixed buffer (reply_buf[248]) during UDP packet processing. Exploitable via 1460-byte UDP messages sent to port 10001, attackers can overwrite return pointers to achieve remote code execution. The global buffer pointer storage and lack of input validation create a reliable exploitation path requiring minimal network access.

Enterprise & DIB Impact

DIB organizations using GV-I/O devices in critical infrastructure control systems face severe risks, including system compromise, data integrity threats, and potential lateral movement. The flaw’s unauthenticated nature and UDP-based attack vector make network segmentation and timely patching essential for enterprise risk mitigation.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →