Buffer Overflow Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-57275
8.3HIGH
What is CVE-2026-57275?
GeoWebPlayer, an addon for GeoVision's software suite, has a vulnerability associated with its Websocket server functionality. The server processes commands originating from localhost, and particularly the connectionInfo command presents a security risk. The handler for this command, handle_connection_info, employs inadequate buffer management, leading to potential buffer overflow due to the unsafe copying of attacker-controlled JSON strings into fixed-size buffers. This flaw could enable an attacker to execute arbitrary code or disrupt system operations.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
