CVE-2026-57875: falha de alta gravidade em GeoVision Inc. GV-LPCLPC2011/2211
GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.5epss 0.7%
probabilidade de exploração
0.7%top 47% das CVEs
exploração observada
nãonenhuma fonte reporta
An unauthenticated
NULL pointer dereference vulnerability exists in the HTTP request parsing logic
of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and
earlier. The vulnerability is caused by improper validation of required HTTP
request metadata before it is used by the affected components. A remote attacker
may exploit this vulnerability by sending a specially crafted HTTP request,
causing the affected process to crash and resulting in a denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
GeoVision Inc. · GV-LPCLPC2011/2211CVEs relacionadas — GeoVision Inc. GV-LPCLPC2011/2211
No mesmo produto, das mais perigosas para as menos.
CVE-2026-57872HIGHGV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)EPSS 1.5%CVE-2026-57878CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)EPSS 1.0%CVE-2026-57880CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)EPSS 0.9%CVE-2026-57879CRITICALGV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)EPSS 0.9%CVE-2026-88276HIGHGV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command InjectionEPSS 0.7%CVE-2026-88277HIGHGV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionEPSS 0.7%