PT-2026-54878 · Geovision · Geowebplayer
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoWebPlayer (affected versions not specified)
Description
GeoWebPlayer, also known as Web Plugin or WS Player, is an addon for GeoVision software that establishes a websocket server to enhance web-interface capabilities. The websocket server accepts commands from localhost, including the
connectionInfo command used to provide camera connection details. The associated function handle connection info contains multiple string copy operations that can overflow. Specifically, the function copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that fail to enforce length limits, leading to a stack-based buffer overflow in the username field.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geowebplayer