Summary
CVE-2026-18754 is a use of hard-coded cryptographic key vulnerability (CWE-321) in the GeoVision GV-AS1620 single-door access controller (GV-Cloud). The device firmware embeds a static RSA private key used by the Lighttpd web server for TLS termination, allowing a network attacker to decrypt HTTPS traffic and impersonate the server. It is rated Critical with a CVSS v3.1 base score of 9.1.
Technical details
- Root cause: The firmware contains an embedded, static RSA private key used by the Lighttpd web server for TLS termination.
- Trigger conditions: An attacker who extracts the static private key, which is shared across affected firmware, can use it against affected devices.
- Attack vector: Network (AV:N); no authentication or user interaction required.
- Impact: Decryption of HTTPS traffic (confidentiality) and server impersonation/spoofing (integrity).
Affected software
- GeoVision GV-AS1620 (GV-Cloud), firmware V1.16.
Severity
- CVSS v3.1 base score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Update the GV-AS1620 (GV-Cloud) firmware to version V1.17 or later, per the GeoVision security advisory.
- If no patch can be applied: Restrict network access to the device’s management interface, avoid exposing it to the internet, and place it on a segmented network reachable only by trusted administrators.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
GV-AS1620

