Buffer Overflow in GeoWebPlayer Web Plugin by GeoVision
CVE-2026-57276

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57276?

The GeoWebPlayer, an essential addon for various GeoVision software, features a websocket server that enhances web-interface functionalities. However, it is susceptible to a buffer overflow vulnerability due to improper handling of commands from localhost. Specifically, the handle_connection_info function erroneously copies JSON strings from attackers into predetermined buffer sizes without imposing necessary length restrictions. This flaw could allow malicious actors to manipulate the websocket server, potentially leading to unauthorized access or system instability.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.