Unauthenticated Directory Traversal Vulnerability in GeoVision Products
CVE-2026-57872
7.5HIGH
What is CVE-2026-57872?
An unauthenticated directory traversal vulnerability exists in the get_fcont.cgi component of GeoVision products, specifically in the GV-LPC2011 and GV-LPC2211 models version V1.12 and earlier. This vulnerability arises from inadequate validation of user-supplied file path inputs. A remote attacker could exploit this weakness by crafting specific requests to access and read unauthorized files within the system's directory, leading to potential information disclosure and compromising sensitive data.
Affected Version(s)
GV-LPCLPC2011/2211 Linux 1.12
GV-LPCLPC2011/2211 Linux 1.13
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University has reported:
