CVE-2026-18754
📛 CVE Title
Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)
Description
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GV
- CVSS severity
- CRITICAL
- CVSS score
- 9.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N- Effective score
- 9.1 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-321 - Reserved
- 2026-08-04
- Published
- 2026-08-04 07:09 UTC
- Last updated
- 2026-08-04 15:03 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/18xxx/CVE-2026-18754.json
- Linked Threat
- CVE-2026-18754 — Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GeoVision Inc. | GV-AS1620 (GV-Cloud) |
V1.16 (affected),
V1.17 (unaffected)
|
Linux |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.geovision.com.tw/cyber_security.php vendor-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-18754.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18754",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T14:38:28.332319Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T15:03:03.492Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "GV-AS1620 (GV-Cloud)",
"vendor": "GeoVision Inc.",
"versions": [
{
"status": "affected",
"version": "V1.16"
},
{
"status": "unaffected",
"version": "V1.17"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Lloyd Lexter Gealon"
}
],
"datePublic": "2026-08-04T00:55:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.</p>"
}
],
"value": "The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing."
}
],
"impacts": [
{
"capecId": "CAPEC-633",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-633 Token Impersonation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T07:09:17.493Z",
"orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"shortName": "GV"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.geovision.com.tw/cyber_security.php"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
"assignerShortName": "GV",
"cveId": "CVE-2026-18754",
"datePublished": "2026-08-04T07:09:17.493Z",
"dateReserved": "2026-08-04T00:55:06.145Z",
"dateUpdated": "2026-08-04T15:03:03.492Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}