GeoVision gv-lpc2011是中国GeoVision公司的视频监控设备。 GeoVision Inc GV-LPCLPC2011/2211 V1.12及之前版本存在异常处理不当漏洞,该漏洞源于HTTP请求解析逻辑中多个CGI组件对所需HTTP请求元数据验证不当,可能导致未经身份验证的远程攻击者通过发送特制HTTP请求触发空指针取消引用,造成进程崩溃并导致拒绝服务。以下版本受到影响:GV-LPC2011 V1.12及之前版本和GV-LPC2211 V1.12及之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 |
affected |
1.13 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GeoVision Inc. | GV-LPCLPC2011/2211 | 1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57881 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr) |
| CVE-2026-57879 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr) |
| CVE-2026-57880 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr) |
| CVE-2026-57878 | 9.8 CRITICAL | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd) |
| CVE-2026-57877 | 8.6 HIGH | GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr) |
| CVE-2026-57874 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi) |
| CVE-2026-57872 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi) |
| CVE-2026-57873 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload |
| CVE-2026-57876 | 7.5 HIGH | GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi) |
No comments yet