12 Advisories 2026
0 Critical
6 High
0 Medium
0 Low
100% Patched

Security Advisory Notifications

Subscribe to receive immediate notifications for critical vulnerabilities and security updates affecting GVision Italia products. Advisories are published per ISO/IEC 29147 guidelines.

Disclosure Timeline: Critical vulnerabilities are disclosed within 90 days of discovery. Direct reports to compliance@gvision.it receive priority handling per our Security Policy.

Resolved Security Advisories 2026

GVSA-2026-001 · August 3, 2026
RESOLVED

GV-ASManager Vulnerability

CVE-2026-18755

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-ASManager access control software
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-002 · August 3, 2026
RESOLVED

GV-AS1620 Controller Vulnerabilities

CVE-2026-18753 CVE-2026-18754

2 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-AS1620 IP access control panel
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-003 · July 22, 2026
RESOLVED

GV-IP Device Utility Vulnerability

CVE-2026-16519

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-IP Device Utility (Windows configuration tool)
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-004 · June 26, 2026
RESOLVED

GV-LPC2011 / LPC2211 Vulnerabilities

CVE-2026-57872 CVE-2026-57873 CVE-2026-57874 CVE-2026-57875 CVE-2026-57876 CVE-2026-57877 CVE-2026-57878 CVE-2026-57879 CVE-2026-57880 CVE-2026-57881

10 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-LPC2011 and GV-LPC2211 licence plate recognition cameras
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-005 · June 24, 2026
RESOLVED

GV-GeoWebPlayer Vulnerabilities

CVE-2026-13125 CVE-2026-13131 CVE-2026-13132 CVE-2026-57264 CVE-2026-57265 CVE-2026-57266 CVE-2026-57267 CVE-2026-57268 CVE-2026-57269 CVE-2026-57270 CVE-2026-57271 CVE-2026-57272 CVE-2026-57273 CVE-2026-57274 CVE-2026-57275 CVE-2026-57276 CVE-2026-57277 CVE-2026-57278

18 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-GeoWebPlayer V1.1.1.0 and earlier
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-006 · June 17, 2026
RESOLVED

GV-VMS V20 and GV-Cloud Vulnerability

CVE-2026-12488

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-VMS V20 with GV-Cloud connection enabled
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-007 · June 17, 2026
RESOLVED

GV-I/O Box 4E Vulnerabilities

CVE-2026-12485 CVE-2026-12486 CVE-2026-12846 CVE-2026-12847 CVE-2026-12848 CVE-2026-12849 CVE-2026-12850 CVE-2026-12851

8 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-I/O Box 4E input and output module
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-008 · May 4, 2026
RESOLVED

GV-ASManager Web Vulnerabilities

CVE-2026-7841

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-ASManager web interface
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-009 · April 27, 2026
RESOLVED

GV-IP Device Utility Vulnerability

CVE-2026-7161

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-IP Device Utility (Windows configuration tool)
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-010 · April 27, 2026
RESOLVED

GV-VMS Web Vulnerabilities

CVE-2026-42369 CVE-2026-42370 CVE-2026-7372

3 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-VMS V20 web interface
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-011 · April 27, 2026
RESOLVED

GV-LPC2011 / LPC2211 Vulnerabilities

CVE-2026-42364 CVE-2026-42365 CVE-2026-42366 CVE-2026-42367 CVE-2026-42368 CVE-2026-7371

6 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-LPC2011 and GV-LPC2211 licence plate recognition cameras
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)
GVSA-2026-012 · March 23, 2026
RESOLVED

GV-Edge Recording Manager Vulnerability

CVE-2026-4606

1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.

Affected Products
GV-Edge Recording Manager
Resolution
Update to the fixed version indicated in the manufacturer advisory.
Certified EU packages are available in the Certification Portal.
📄 View Security Advisory (PDF)

Resolved Security Advisories 2025

GVSA-2025-001 · April 9, 2025
RESOLVED

GV-ASManager Software Vulnerabilities – Patches Distributed

HIGH CVE-2025-26263 CVE-2025-26264

Multiple vulnerabilities were identified in the GeoVision ASManager software (Windows application) affecting authentication and session management. As Terminal Manufacturer, GVision Italia coordinated the patch distribution for EU deployments and provided additional hardening guidelines including enhanced input validation, secure session handling, and NIS2-compliant logging mechanisms.

Affected Software
GeoVision GV-ASManager version 6.1.2.0 and earlier
Fixed in version 6.2.0
Resolution
Update to GV-ASManager version 6.2.0 or later
Download available from GeoVision official site or GVision Italia portal
📄 View Security Advisory (PDF)
GVSA-2025-002 · February 3, 2025
RESOLVED

GV-ASManager Multiple Security Vulnerabilities – Software Update Required

HIGH CVE-2024-56898 CVE-2024-56901 CVE-2024-56902 CVE-2024-56903 CVSS 8.8/8.1/7.5/6.5

Critical security vulnerabilities affecting GeoVision ASManager web application (ASWeb component) including broken access control, CSRF, information disclosure, and request method tampering. GVision Italia, acting as Terminal Manufacturer for the EU market, coordinated the patch distribution and implemented comprehensive security configurations including: Guest account hardening, enhanced authorization checks at multiple layers, input sanitization per OWASP guidelines, and additional EU-specific security controls mandated by the Cyber Resilience Act.

Affected Software
GeoVision GV-ASManager version 6.1.1.0 and earlier
Fixed in version 6.2.0
Resolution
Update to GV-ASManager version 6.2.0 or later
Security configuration package available for EU deployments
📄 View Security Advisory (PDF)

✓ Closed Security Notices 2026

GVSN-2026-001 · March 2026
NOT AFFECTED

Broadcom NetXtreme bnxt_en Driver: Inventory Assessment Completed

CVE-2026-23041 Linux Kernel · bnxt_en Assessment Closed

Following the publication of CVE-2026-23041 (null pointer dereference in the Linux kernel bnxt_en driver, Broadcom NetXtreme chipset family, kernel < 6.13.3), GVision Italia initiated a full inventory assessment of all distributed devices, including custom embedded units produced for enterprise customers under confidential supply agreements.

The assessment, completed in March 2026, determined that none of the devices within GVision Italia’s distributed inventory are affected by this vulnerability. No Broadcom NetXtreme chipset subject to the vulnerable bnxt_en PTP initialization path was found in any product line, including catalogue products and non-catalogue enterprise devices.

Scope Assessed
Full GVision Italia product catalogue: PoE switches, cameras, NVR/VMS appliances
Custom embedded devices produced for enterprise clients (non-catalogue)
Assessment method: hardware inventory review + kernel driver audit
Determination
No affected units identified: CVE-2026-23041 does not apply to GVision Italia distributed products
No customer action required · Notice closed
Process Note: This notice was opened on February 4, 2026 following CVE publication and closed upon completion of inventory verification within 30 days, well within the 90-day disclosure timeline required by ISO/IEC 29147. For further information contact compliance@gvision.it.

Closed notices represent completed assessments with a “Not Affected” or resolved determination. · Security Policy

Terminal Manufacturer Responsibility
GVision Italia S.r.l., as the appointed Terminal Manufacturer for GeoVision Inc. products in the European Union market, maintains full responsibility for security patch distribution and deployment guidance. Our ISO/IEC 27001:2022 certified processes ensure:
  • Immediate response to vulnerability disclosures from GeoVision Inc. CNA
  • Comprehensive testing of all patches in EU operational environments
  • Additional security configurations per NIS2 Directive and Cyber Resilience Act requirements
  • Complete audit trail and documentation for all software modifications
  • Coordinated disclosure within 90 days per ISO/IEC 29147 guidelines

Vulnerability Disclosure: Security Policy · RSS: Subscribe to Feed

CVE Program: GVision Italia, CVE Numbering Authority accreditata sotto ENISA Root (5 maggio 2026) · in coordinamento con GeoVision Inc. CNA

© 2026 GVision Italia S.r.l. – ISO/IEC 27001:2022 Certified

GVision Italia è GeoVision Italia: immettiamo sul mercato europeo i sistemi GeoVision e ne rispondiamo, come unica azienda italiana accreditata CVE Numbering Authority sotto ENISA Root.