{"api_version":"1","generated_at":"2026-08-06T04:31:42+00:00","cve":"CVE-2026-18754","urls":{"html":"https://cve.report/CVE-2026-18754","api":"https://cve.report/api/cve/CVE-2026-18754.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18754","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18754"},"summary":{"title":"Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","state":"PUBLISHED","assigner":"GV","published_at":"2026-08-04 08:16:34","updated_at":"2026-08-04 16:16:22"},"problem_types":["CWE-321","CWE-321 CWE-321 Use of hard-coded cryptographic key"],"metrics":[{"version":"3.1","source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","name":"https://www.geovision.com.tw/cyber_security.php","refsource":"0df08a0e-a200-4957-9bb0-084f562506f9","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18754","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18754","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"GeoVision Inc.","product":"GV-AS1620 (GV-Cloud)","version":"affected V1.16","platforms":["Linux"]},{"source":"CNA","vendor":"GeoVision Inc.","product":"GV-AS1620 (GV-Cloud)","version":"unaffected V1.17","platforms":["Linux"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lloyd Lexter Gealon","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"18754","cve":"CVE-2026-18754","epss":"0.003130000","percentile":"0.236320000","score_date":"2026-08-05","updated_at":"2026-08-06 00:00:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-18754","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-04T14:38:28.332319Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-04T15:03:03.492Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Linux"],"product":"GV-AS1620 (GV-Cloud)","vendor":"GeoVision Inc.","versions":[{"status":"affected","version":"V1.16"},{"status":"unaffected","version":"V1.17"}]}],"credits":[{"lang":"en","type":"finder","value":"Lloyd Lexter Gealon"}],"datePublic":"2026-08-04T00:55:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.</p>"}],"value":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing."}],"impacts":[{"capecId":"CAPEC-633","descriptions":[{"lang":"en","value":"CAPEC-633 Token Impersonation"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-321","description":"CWE-321 Use of hard-coded cryptographic key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-04T07:09:17.493Z","orgId":"0df08a0e-a200-4957-9bb0-084f562506f9","shortName":"GV"},"references":[{"tags":["vendor-advisory"],"url":"https://www.geovision.com.tw/cyber_security.php"}],"source":{"discovery":"UNKNOWN"},"title":"Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"0df08a0e-a200-4957-9bb0-084f562506f9","assignerShortName":"GV","cveId":"CVE-2026-18754","datePublished":"2026-08-04T07:09:17.493Z","dateReserved":"2026-08-04T00:55:06.145Z","dateUpdated":"2026-08-04T15:03:03.492Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-04 08:16:34","lastModifiedDate":"2026-08-04 16:16:22","problem_types":["CWE-321","CWE-321 CWE-321 Use of hard-coded cryptographic key"],"metrics":{"cvssMetricV31":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T14:38:28.332319Z","id":"CVE-2026-18754","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18754","Ordinal":"1","Title":"Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV","CVE":"CVE-2026-18754","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18754","Ordinal":"1","NoteData":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","Type":"Description","Title":"Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV"}]}}}