NULL Pointer Dereference in GeoVision Surveillance Systems
CVE-2026-57875
7.5HIGH
What is CVE-2026-57875?
A NULL pointer dereference vulnerability has been identified in the HTTP request parsing logic of multiple CGI components within GeoVision's GV-LPC2011 and GV-LPC2211 systems, particularly in versions V1.12 and earlier. This vulnerability arises from the improper validation of essential HTTP request metadata, which could allow an unauthenticated remote attacker to exploit the flaw. By crafting and sending a malicious HTTP request, an attacker may cause the affected service to crash, leading to a denial of service situation. Organizations utilizing these GeoVision products are advised to take immediate action to mitigate potential threats.
Affected Version(s)
GV-LPCLPC2011/2211 Linux 1.12
GV-LPCLPC2011/2211 Linux 1.13
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University has reported:
