PT-2026-52669 · Geovision · Gv-Lpc2211+1
CVE-2026-57872
·
Published
2026-06-26
·
Updated
2026-07-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-LPC2011 versions prior to 1.13
GeoVision GV-LPC2211 versions prior to 1.13
Description
An unauthenticated directory traversal issue exists in the 'get fcont.cgi' endpoint. This occurs due to insufficient validation of user-supplied file path input before the CGI component accesses the requested file. A remote attacker can send a crafted request to read arbitrary files accessible to the affected process, leading to information disclosure. Directory traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations
Update GeoVision GV-LPC2011 to a version newer than 1.12.
Update GeoVision GV-LPC2211 to a version newer than 1.12.
Restrict access to the 'get fcont.cgi' endpoint to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-Lpc2011
Gv-Lpc2211