PT-2026-52674 · Geovision · Gv-Lpc2211+1
CVE-2026-57877
·
Published
2026-06-26
·
Updated
2026-06-26
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-LPC2011 versions prior to V1.13
GeoVision GV-LPC2211 versions prior to V1.13
Description
An unauthenticated format string vulnerability exists in the
vlsvr component. The issue occurs due to improper handling of externally controlled input during log message formatting within the login processing path. A remote attacker can exploit this by sending crafted login data, which may lead to information disclosure, memory corruption, or a denial of service. A format string vulnerability is a type of software bug where an application fails to properly validate input used as a format string, allowing an attacker to read or write to memory.Recommendations
Update GeoVision GV-LPC2011 to a version later than V1.12.
Update GeoVision GV-LPC2211 to a version later than V1.12.
Fix
DoS
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-Lpc2011
Gv-Lpc2211