Stack-based Buffer Overflow in GeoVision GV-LPC2011 and GV-LPC2211
CVE-2026-57878

9.8CRITICAL

Key Information:

Vendor
CVE Published:
26 June 2026

What is CVE-2026-57878?

An unauthenticated stack-based buffer overflow vulnerability exists in the thttpd server component of GeoVision GV-LPC2011 and GV-LPC2211. This vulnerability arises from inadequate bounds checking when handling web request parameters, specifically under certain request conditions. A remote attacker can exploit this weakness by sending specially crafted HTTP requests containing overly long input, leading to potential memory corruption, denial of service, and the possibility of arbitrary code execution.

Affected Version(s)

GV-LPCLPC2011/2211 Linux 1.12

GV-LPCLPC2011/2211 Linux 1.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University has reported:
.