CVE-2026-57875: high-severity vulnerability in GeoVision Inc. GV-LPCLPC2011/2211
GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
An unauthenticated
NULL pointer dereference vulnerability exists in the HTTP request parsing logic
of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and
earlier. The vulnerability is caused by improper validation of required HTTP
request metadata before it is used by the affected components. A remote attacker
may exploit this vulnerability by sending a specially crafted HTTP request,
causing the affected process to crash and resulting in a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
GeoVision Inc. · GV-LPCLPC2011/2211Related CVEs — GeoVision Inc. GV-LPCLPC2011/2211
In the same product, most dangerous first.
CVE-2026-57872HIGHGV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)EPSS 1.5%CVE-2026-57878CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)EPSS 1.0%CVE-2026-57880CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)EPSS 0.9%CVE-2026-57879CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)EPSS 0.9%CVE-2026-88276HIGHGV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command InjectionEPSS 0.7%CVE-2026-88277HIGHGV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionEPSS 0.7%