Unauthenticated Out-of-Bounds Write Vulnerability in GeoVision Products
CVE-2026-57876

7.5HIGH

Key Information:

Vendor
CVE Published:
26 June 2026

What is CVE-2026-57876?

An out-of-bounds write vulnerability exists in the onvif.cgi script of GeoVision GV-LPC2011 and GV-LPC2211 models, caused by inadequate bounds checking during HTTP request body processing. This oversight allows remote attackers to send specially crafted requests containing excessive input, potentially leading to memory corruption and resulting in a denial-of-service condition, disrupting normal operations.

Affected Version(s)

GV-LPCLPC2011/2211 Linux 1.12

GV-LPCLPC2011/2211 Linux 1.13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University has reported:
.