A vulnerability marked as critical has been reported in GeoVision GV-IO Box 4E up to 2.09/2.11. Impacted is an unknown function of the component Send Message Handler. Performing a manipulation results in stack-based buffer overflow.

This vulnerability is known as CVE-2026-12846. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.