A vulnerability classified as critical has been found in GeoVision GV-IO Box 4E up to 2.09/2.11. The impacted element is an unknown function of the component Send Message Handler. The manipulation leads to stack-based buffer overflow.

This vulnerability is uniquely identified as CVE-2026-12848. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.