Buffer Overflow in GeoWebPlayer Websocket Server by GeoVision
CVE-2026-57273
8.3HIGH
What is CVE-2026-57273?
The GeoWebPlayer, part of the GeoVision software suite, features a websocket server designed to enhance web-interface functionalities. It processes commands from localhost, including one known as connectionInfo, which delivers critical details for camera connections. Within the handle_connection_info operation, there are multiple instances of string copying that can result in buffer overflow vulnerabilities due to the lack of enforced length constraints in fixed-size buffers. This flaw exposes the system to potential exploitation, allowing attackers to potentially execute arbitrary code or disrupt services.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
