PT-2026-54883 · Geovision · Geowebplayer

·

CVE-2026-57278

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoWebPlayer (affected versions not specified)
Description GeoWebPlayer, also known as Web Plugin or WS Player, is an addon for GeoVision software that establishes a websocket server to enhance web-interface capabilities. The websocket server accepts commands from localhost, including the connectionInfo command used to provide camera connection details. The associated handle connection info() function contains multiple string copy operations that can overflow. Specifically, the function copies attacker-controlled JSON strings into fixed-size buffers using manual byte-by-byte loops that fail to enforce length limits, leading to a stack-based buffer overflow in the ip field.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57278

Affected Products

Geowebplayer