CVE-2026-57875: fallo de gravedad alta en GeoVision Inc. GV-LPCLPC2011/2211
GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.7%
probabilidad de explotación
0.7%top 47% de las CVE
explotación observada
noninguna fuente lo reporta
An unauthenticated
NULL pointer dereference vulnerability exists in the HTTP request parsing logic
of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and
earlier. The vulnerability is caused by improper validation of required HTTP
request metadata before it is used by the affected components. A remote attacker
may exploit this vulnerability by sending a specially crafted HTTP request,
causing the affected process to crash and resulting in a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
GeoVision Inc. · GV-LPCLPC2011/2211CVEs relacionadas — GeoVision Inc. GV-LPCLPC2011/2211
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-57872HIGHGV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)EPSS 1.5%CVE-2026-57878CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)EPSS 1.0%CVE-2026-57880CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)EPSS 0.9%CVE-2026-57879CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)EPSS 0.9%CVE-2026-88276HIGHGV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command InjectionEPSS 0.7%CVE-2026-88277HIGHGV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionEPSS 0.7%