CVE-2026-103098 (GCVE-0-2026-103098)

Vulnerability from cvelistv5 – Published: 2026-10-02 00:15 – Updated: 2026-10-02 00:15
VLAI
Title
GV-Eye Sensitive information exposure in URL query parameter Vulnerability
Summary
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
CWE
  • CWE-319 - Cleartext transmission of sensitive information
References
Impacted products
Vendor Product Version
GeoVision Inc. GV-Eye Affected: V3.6.0
Unaffected: V3.7.2
    cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-30 02:15
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageName": "tw.com.geovision.gveye",
          "platforms": [
            "Android"
          ],
          "product": "GV-Eye",
          "vendor": "GeoVision Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "V3.6.0"
            },
            {
              "status": "unaffected",
              "version": "V3.7.2"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*",
                  "vulnerable": false
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Lloyd Lexter Gealon"
        }
      ],
      "datePublic": "2026-09-30T02:15:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u0026nbsp; The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
            }
          ],
          "value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u00a0 The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-158",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-158 Sniffing Network Traffic"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-319",
              "description": "CWE-319 Cleartext transmission of sensitive information",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T00:15:17.848Z",
        "orgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "shortName": "GV"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.geovision.com.tw/cyber_security.php"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "GV-Eye Sensitive information exposure in URL query parameter Vulnerability",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "0df08a0e-a200-4957-9bb0-084f562506f9",
    "assignerShortName": "GV",
    "cveId": "CVE-2026-103098",
    "datePublished": "2026-10-02T00:15:17.848Z",
    "dateReserved": "2026-09-30T02:10:02.128Z",
    "dateUpdated": "2026-10-02T00:15:17.848Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "packageName": "tw.com.geovision.gveye",
                "platforms": [
                  "Android"
                ],
                "product": "GV-Eye",
                "vendor": "GeoVision Inc.",
                "versions": [
                  {
                    "status": "affected",
                    "version": "V3.6.0"
                  },
                  {
                    "status": "unaffected",
                    "version": "V3.7.2"
                  }
                ]
              }
            ],
            "source": "0df08a0e-a200-4957-9bb0-084f562506f9"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\u00a0 The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key"
          }
        ],
        "id": "CVE-2026-103098",
        "lastModified": "2026-10-02T01:16:43.193",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 3.6,
              "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-02T01:16:43.193",
        "references": [
          {
            "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "url": "https://www.geovision.com.tw/cyber_security.php"
          }
        ],
        "sourceIdentifier": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "vulnStatus": "Received",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-319"
              }
            ],
            "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
            "type": "Secondary"
          }
        ]
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…