Websocket Server Vulnerability in GeoWebPlayer from GeoVision
CVE-2026-57265

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57265?

The GeoWebPlayer, which enhances functionalities for various GeoVision software, possesses a vulnerability in its websocket server. This server accepts commands from localhost but lacks proper validation for the index value used to access arrays. As a result, attackers could exploit this flaw, leading to out-of-bounds access and potential manipulation of critical data structures within the system, thereby jeopardizing the safety and integrity of applications relying on GeoWebPlayer.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.