CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2021-47795Public Exploit

GeoVision GeoWebServer - Path Traversal (CVE-2021-47795)

PublishedJan 15, 2026
First SeenAug 19, 2026
Last Seen
Reported
CVSS8.7
iotweb_server

Description

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

psychologyCrowdSec Analysis

CVE-2021-47795 is a high-severity vulnerability in GeoVision GeoWebServer 5.3.3 involving improper input sanitization in the WebStrings.srf endpoint. Unauthenticated remote attackers may exploit path traversal and injection flaws to access local system files, perform cross-site scripting attacks, and potentially execute malicious code on the server.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec network data shows that most actors exploiting CVE-2021-47795 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2021-47795 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2021-47795 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers target /Visitor/bin/WebStrings.srf and related /Visitor/ paths, supplying encoded path traversal sequences to access files such as windows/win.ini. Requests may also place script payloads in the obj_name parameter to trigger reflected XSS.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-01-15
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.