PT-2026-52670 · Geovision · Gv-Lpc2211+1
CVE-2026-57873
·
Published
2026-06-26
·
Updated
2026-06-26
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-LPC2011 versions prior to 1.13
GeoVision GV-LPC2211 versions prior to 1.13
Description
An unauthenticated NULL pointer dereference occurs in the 'IEEE8021x upload.cgi' endpoint. This issue stems from improper validation of multipart upload headers during the processing of certificate-related upload fields. A remote attacker can trigger a crash of the CGI process by sending a malformed multipart request, leading to a denial of service. A NULL pointer dereference is a condition where a program attempts to read or write to a memory address that is NULL, typically causing the application to crash.
Recommendations
Update GeoVision GV-LPC2011 to version 1.13 or later.
Update GeoVision GV-LPC2211 to version 1.13 or later.
Restrict access to the 'IEEE8021x upload.cgi' endpoint to minimize the risk of exploitation.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-Lpc2011
Gv-Lpc2211