Format String Vulnerability in GeoVision GV-LPC2011 and GV-LPC2211 Products
CVE-2026-57877
8.6HIGH
What is CVE-2026-57877?
A format string vulnerability has been identified in GeoVision's GV-LPC2011 and GV-LPC2211 products, affecting versions V1.12 and earlier. The issue arises from the improper handling of user-controlled input in the login processing phase, particularly during log message formatting. This security flaw allows remote attackers to craft malicious login data, risking potential information disclosure, memory corruption, or even denial of service, thereby compromising the integrity and availability of the affected systems.
Affected Version(s)
GV-LPCLPC2011/2211 Linux 1.12
GV-LPCLPC2011/2211 Linux 1.13
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University has reported:
