Buffer Overflow Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-57275

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57275?

GeoWebPlayer, an addon for GeoVision's software suite, has a vulnerability associated with its Websocket server functionality. The server processes commands originating from localhost, and particularly the connectionInfo command presents a security risk. The handler for this command, handle_connection_info, employs inadequate buffer management, leading to potential buffer overflow due to the unsafe copying of attacker-controlled JSON strings into fixed-size buffers. This flaw could enable an attacker to execute arbitrary code or disrupt system operations.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.