Buffer Overflow in GeoWebPlayer Enhances Potential Security Risks in GeoVision Software
CVE-2026-57278
What is CVE-2026-57278?
The GeoWebPlayer, also known as 'Web Plugin' in the GV-VMS documentation, enhances web interfaces for GeoVision software by creating a websocket server. This server accepts various commands, including 'connectionInfo', which is intended to facilitate camera connections. However, the implementation of the 'handle_connection_info' function is flawed, as it features multiple string copy operations that are subject to buffer overflow vulnerabilities. Specifically, attacker-controlled JSON strings are copied into fixed-size buffers without adequate length checks, leading to potential exploitation and increased risk of unauthorized access to sensitive data.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
