PT-2026-52674 · Geovision · Gv-Lpc2211+1

CVE-2026-57877

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions GeoVision GV-LPC2011 versions prior to V1.13 GeoVision GV-LPC2211 versions prior to V1.13
Description An unauthenticated format string vulnerability exists in the vlsvr component. The issue occurs due to improper handling of externally controlled input during log message formatting within the login processing path. A remote attacker can exploit this by sending crafted login data, which may lead to information disclosure, memory corruption, or a denial of service. A format string vulnerability is a type of software bug where an application fails to properly validate input used as a format string, allowing an attacker to read or write to memory.
Recommendations Update GeoVision GV-LPC2011 to a version later than V1.12. Update GeoVision GV-LPC2211 to a version later than V1.12.

Fix

DoS

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57877

Affected Products

Gv-Lpc2011
Gv-Lpc2211