WolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos disclosed vulnerabilities across three products: WolfSSL (3 CVEs involving improper input validation and integer underflow), GeoVision (37 CVEs across 14 advisories covering memory corruption, command injection, buffer overflows, privilege escalation, XSS, weak encryption, and authentication flaws), and VTK-DICOM (1 heap-based buffer overflow). All vulnerabilities have been patched by their respective vendors. Snort coverage is available for exploitation detection.
Detection / Hunteropenrouter
What Happened
Security researchers at Cisco Talos found a total of 41 security flaws across three software products: WolfSSL (a lightweight encryption library), GeoVision (security cameras and access control systems), and VTK-DICOM (a library for processing medical imaging data). The most severe batch affects GeoVision, with 37 vulnerabilities that could allow attackers to take control of devices, run malicious commands, escalate privileges, or intercept data. The VTK-DICOM flaw could allow a specially crafted medical image file to crash or compromise software that opens it. All affected vendors have released patches. Organizations using any of these products should update to the latest versions immediately and verify that their Snort intrusion detection rules are current.
Key Takeaways
- Cisco Talos disclosed 3 vulnerabilities in WolfSSL (2 improper input validation, 1 integer underflow), all patched.
- 14 GeoVision advisories covering 37 CVEs were released, spanning memory corruption, OS command injection, buffer overflows, privilege escalation, XSS, guessable session cookies, insufficient encryption, out-of-bounds reads, and lack of authentication.
- A heap-based buffer overflow vulnerability (CVE-2026-22879) was found in VTK-DICOM, an open-source library for parsing DICOM medical imaging data.
- Snort coverage is available for detecting exploitation of these vulnerabilities via the latest Snort rule sets.
- All vulnerabilities have been patched by their respective vendors in accordance with Cisco's third-party vulnerability disclosure policy.
Affected Systems
- WolfSSL (open-source TLS library for embedded systems)
- GeoVision security cameras, monitoring solutions, access control systems, and machine-identification products
- VTK-DICOM (open-source library for parsing DICOM medical imaging data within the Visualization Toolkit)
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-28739 | WolfSSL | Improper input validation vulnerability in WolfSSL. | |
| CVE-2026-25106 | WolfSSL | Improper input validation vulnerability in WolfSSL. | |
| CVE-2026-33091 | WolfSSL | Integer underflow vulnerability in WolfSSL. | |
| CVE-2026-12488 | GeoVision | Memory corruption vulnerability in GeoVision products. | |
| CVE-2026-12486 | GeoVision | OS command injection vulnerability in GeoVision products. | |
| CVE-2026-12849 | GeoVision | OS command injection vulnerability in GeoVision products. | |
| CVE-2026-12850 | GeoVision | OS command injection vulnerability in GeoVision products. | |
| CVE-2026-12851 | GeoVision | OS command injection vulnerability in GeoVision products. | |
| CVE-2026-12485 | GeoVision | Buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-12846 | GeoVision | Buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-12847 | GeoVision | Buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-12848 | GeoVision | Buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-42370 | GeoVision | Stack overflow vulnerability in GeoVision products. | |
| CVE-2026-7372 | GeoVision | Stack overflow vulnerability in GeoVision products. | |
| CVE-2026-42369 | GeoVision | Stack overflow vulnerability in GeoVision products. | |
| CVE-2026-42368 | GeoVision | Privilege escalation vulnerability in GeoVision products. | |
| CVE-2026-42367 | GeoVision | Privilege escalation vulnerability in GeoVision products. | |
| CVE-2026-7371 | GeoVision | Reflected cross-site scripting (XSS) vulnerability in GeoVision products. | |
| CVE-2026-42366 | GeoVision | Reflected cross-site scripting (XSS) vulnerability in GeoVision products. | |
| CVE-2026-42364 | GeoVision | OS command injection vulnerability in GeoVision products. | |
| CVE-2026-42365 | GeoVision | Guessable session cookie vulnerability in GeoVision products. | |
| CVE-2026-7161 | GeoVision | Insufficient encryption vulnerability in GeoVision products. | |
| CVE-2026-57273 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-57274 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-57275 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-57276 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-57277 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-57278 | GeoVision | Stack-based buffer overflow vulnerability in GeoVision products. | |
| CVE-2026-13131 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-13132 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57264 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57265 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57266 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57267 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57268 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57269 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57270 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57271 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-57272 | GeoVision | Out-of-bounds read vulnerability in GeoVision products. | |
| CVE-2026-13125 | GeoVision | Lack of authentication vulnerability in GeoVision products. | |
| CVE-2026-22879 | VTK-DICOM | Heap-based buffer overflow vulnerability in VTK-DICOM library for parsing DICOM medical data. |
Attack Chain
- Reconnaissance: Attacker identifies target systems running unpatched WolfSSL, GeoVision, or VTK-DICOM software
- Initial Access: Attacker exploits one of the disclosed vulnerabilities (e.g., OS command injection, lack of authentication, or XSS on GeoVision devices) to gain entry
- Execution: Attacker leverages memory corruption, buffer overflow, or command injection to execute arbitrary code on the target system
- Privilege Escalation: Attacker uses privilege escalation vulnerabilities (CVE-2026-42368, CVE-2026-42367) to elevate access on compromised GeoVision devices
- Persistence/Exfiltration: Attacker maintains access via guessable session cookies or insufficient encryption and exfiltrates data or pivots to additional targets
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: Yes
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Snort
Snort coverage is available for detecting exploitation of these vulnerabilities. Users should download the latest rule sets from Snort.org. Detailed advisories are available on the Talos Intelligence website.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR may detect post-exploitation activity such as command execution or privilege escalation on GeoVision devices, but IoT/embedded devices like cameras may not run EDR agents. WolfSSL and VTK-DICOM exploitation at the library level may not produce distinct EDR telemetry. |
| Network Visibility | High | Snort rules are available for network-based detection of exploitation attempts. GeoVision devices are network-accessible, and attacks targeting them would likely generate detectable network traffic. |
| Detection Difficulty | Moderate | Snort coverage is available for network-level detection, but identifying exploitation of library-level vulnerabilities (WolfSSL, VTK-DICOM) may require application-specific telemetry. GeoVision IoT devices may have limited logging capabilities. |
Required Log Sources
- Snort/Suricata IDS alerts
- Network flow logs for GeoVision device traffic
- Web server logs for GeoVision web interface access
- Authentication logs for GeoVision devices
- Application logs for VTK-DICOM processing systems
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for network traffic patterns indicating exploitation attempts against GeoVision web interfaces, particularly unusual HTTP requests that may target OS command injection or XSS vulnerabilities. | Network IDS alerts, web proxy logs, GeoVision device web server logs | Initial Access | Medium — legitimate administrative access to GeoVision web interfaces may generate similar traffic patterns. |
| If you have visibility into process activity on systems processing DICOM data, consider hunting for abnormal process behavior or crashes that may indicate exploitation of the VTK-DICOM heap-based buffer overflow. | EDR process telemetry, application crash logs, Windows Event Logs | Execution | Low — abnormal process crashes during DICOM parsing are uncommon in normal operations. |
| Consider hunting for privilege escalation activity on GeoVision devices by monitoring for unexpected administrative actions or configuration changes following unauthenticated access. | Device audit logs, authentication logs, network session logs | Privilege Escalation | Medium — legitimate administrator actions may resemble malicious privilege escalation. |
Control Gaps
- IoT/embedded devices like GeoVision cameras typically lack EDR agents, limiting host-based detection
- Library-level exploitation of WolfSSL or VTK-DICOM may not generate distinct network signatures beyond what Snort provides
- Limited logging on embedded GeoVision devices may hinder post-exploitation investigation
Key Behavioral Indicators
- Unusual HTTP requests to GeoVision device web interfaces containing command injection payloads
- Unexpected process execution or crashes on systems running VTK-DICOM when processing DICOM files
- Authentication events on GeoVision devices from unexpected source IPs
- Network traffic to GeoVision devices from non-administrative network segments
False Positive Assessment
Low — Snort rules for these specific vulnerabilities are expected to be targeted; however, legitimate administrative access to GeoVision web interfaces may generate some benign alerts if network patterns overlap.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Prioritize patching all GeoVision devices, WolfSSL deployments, and VTK-DICOM installations to the latest vendor-released versions.
- If your organization uses Snort or Suricata, consider updating to the latest rule sets from Snort.org to enable detection of exploitation attempts against these vulnerabilities.
- If GeoVision devices are internet-facing, consider restricting network access to authorized administrative IP ranges only until patches are applied.
Infrastructure Hardening
- Evaluate whether GeoVision security cameras and access control systems can be segmented onto a dedicated IoT network with restricted access to corporate resources.
- Consider implementing network-level authentication or VPN requirements for accessing GeoVision device web interfaces.
- If applicable, review and enforce least-privilege network policies for systems running VTK-DICOM, especially those processing untrusted DICOM files from external sources.
User Protection
- Consider deploying network-based intrusion detection (Snort/Suricata) at perimeter and internal segmentation boundaries to detect exploitation attempts against GeoVision devices.
- If your organization processes external DICOM medical imaging files, evaluate whether file validation or sandboxing can be applied before files reach VTK-DICOM processing pipelines.
Security Awareness
- Consider notifying relevant teams (physical security, medical imaging, embedded systems) about the availability of patches for their respective product categories.
- If applicable, remind staff that security camera and access control systems require the same patch management rigor as traditional IT endpoints.