# CVE-2021-47795: GeoVision GeoWebServer - Path Traversal

> Live exploitation tracking for CVE-2021-47795 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2021-47795

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** GeoVision GeoWebServer
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** iot, web_server

## Description

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

## CrowdSec analysis

[CVE-2021-47795](https://euvd.enisa.europa.eu/vulnerability/CVE-2021-47795) is a high-severity vulnerability in GeoVision GeoWebServer 5.3.3 involving improper input sanitization in the WebStrings.srf endpoint. Unauthenticated remote attackers may exploit path traversal and injection flaws to access local system files, perform cross-site scripting attacks, and potentially execute malicious code on the server.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec network data shows that most actors exploiting CVE-2021-47795 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2021-47795 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2021-47795 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers target `/Visitor/bin/WebStrings.srf` and related `/Visitor/` paths, supplying encoded path traversal sequences to access files such as `windows/win.ini`. Requests may also place script payloads in the `obj_name` parameter to trigger reflected XSS.

## Timeline

- 2026-01-15: CVE Published. CVE-2021-47795 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2021-47795 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2021-47795 for the first time.

## References

- https://www.geovision.com.tw/cyber_security.php
- https://www.vulncheck.com/advisories/geovision-geowebserver-local-file-inclusion
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-47795.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2021-47795) follows observed exploitation activity for CVE-2021-47795. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
