Buffer Overflow in GeoWebPlayer Enhances Potential Security Risks in GeoVision Software
CVE-2026-57278

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57278?

The GeoWebPlayer, also known as 'Web Plugin' in the GV-VMS documentation, enhances web interfaces for GeoVision software by creating a websocket server. This server accepts various commands, including 'connectionInfo', which is intended to facilitate camera connections. However, the implementation of the 'handle_connection_info' function is flawed, as it features multiple string copy operations that are subject to buffer overflow vulnerabilities. Specifically, attacker-controlled JSON strings are copied into fixed-size buffers without adequate length checks, leading to potential exploitation and increased risk of unauthorized access to sensitive data.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.